SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-29447

An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication.

MEDIUM 5.3EPSS 0.36%

Does this matter?

Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.

Description

An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.36% probability · 30th percentile
CISA KEV
Not listed
Weakness
CWE-522
Affected
ptc/kepware kepserverex · ptc/thingworx kepware server · ptc/thingworx industrial connectivity
Source
ot-cert@dragos.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.