← Back

CVE-2023-27855

nvd nist
Published: Mar 22, 2023Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could overwrite existing executable files with attacker-controlled, malicious contents, potentially causing remote code execution.

Affected (8)

Thinmanager
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
From 11.0.0 to 11.0.5
From 11.1.0 to 11.1.5
From 11.2.0 to 11.2.6
From 12.0.0 to 12.0.4
From 12.1.0 to 12.1.5
From 6.0.0 to 10.0.2
Version 13.0.0
Version 13.0.1

References (2)

Source: PSIRT@rockwellautomation.com
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory

Timeline

No history available yet.