CVE Vulnerabilities

CVE-2023-29447

Insufficiently Protected Credentials

Published: Jan 10, 2024 | Modified: Jan 18, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Kepware_kepserverex Ptc 6.0.2107.0 (including) 6.14.263.0 (including)

Potential Mitigations

References