Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-27855


In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could overwrite existing executable files with attacker-controlled, malicious contents, potentially causing remote code execution.


Published

2023-03-22T00:15:12.670

Last Modified

2024-11-21T07:53:35.047

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rockwellautomation thinmanager ≤ 10.0.2 Yes
Application rockwellautomation thinmanager ≤ 11.0.5 Yes
Application rockwellautomation thinmanager ≤ 11.1.5 Yes
Application rockwellautomation thinmanager ≤ 11.2.6 Yes
Application rockwellautomation thinmanager ≤ 12.0.4 Yes
Application rockwellautomation thinmanager ≤ 12.1.5 Yes
Application rockwellautomation thinmanager 13.0.0 Yes
Application rockwellautomation thinmanager 13.0.1 Yes

References