Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-2915


The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists when the ThinManager software processes a certain function. If exploited, an unauthenticated remote threat actor can delete arbitrary files with system privileges. A malicious user could exploit this vulnerability by sending a specifically crafted synchronization protocol message resulting in a denial-of-service condition.


Published

2023-08-17T16:15:09.693

Last Modified

2024-11-21T07:59:33.727

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rockwellautomation thinmanager_thinserver ≤ 11.0.6 Yes
Application rockwellautomation thinmanager_thinserver ≤ 11.1.6 Yes
Application rockwellautomation thinmanager_thinserver ≤ 11.2.7 Yes
Application rockwellautomation thinmanager_thinserver ≤ 12.0.5 Yes
Application rockwellautomation thinmanager_thinserver ≤ 12.1.6 Yes
Application rockwellautomation thinmanager_thinserver ≤ 13.0.2 Yes
Application rockwellautomation thinmanager_thinserver 13.1.0 Yes

References