CVE-2023-29447: PTC Kepware Kepserverex

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication.

Affected products

  • PTC Kepware Kepserverex: from 6.0.2107.0, up to and including 6.14.263.0
  • PTC Thingworx Industrial Connectivity: from 8.0, up to and including 8.5
  • PTC Thingworx Kepware Server: from 6.8, up to and including 6.14.263.0

Published 2024-01-10. Last modified 2026-06-17.