Vulnerability CVE-2023-29446


Published: 2024-01-10

Description:
An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows an adversary to capture NLTMv2 hashes and potentially crack them offline. 

 References:
https://www.cisa.gov/news-events/ics-advisories/icsa-23-243-03
https://www.ptc.com/en/support/article/cs399528
https://www.dragos.com/advisory/ptcs-kepserverex-vulnerabilities/

Copyright 2026, cxsecurity.com

 

Back to Top