Vulnerabilities > PTC > Thingworx Industrial Connectivity > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-10 | CVE-2023-29446 | Improper Input Validation vulnerability in PTC products An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. | 4.7 |
2024-01-10 | CVE-2023-29447 | Insufficiently Protected Credentials vulnerability in PTC products An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication. | 5.3 |