← Back

CVE-2023-27857

nvd nist
Published: Mar 22, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's ThinManager ThinServer.  An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation.

Affected (6)

Thinmanager
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
From 11.0.0 to 11.0.5
From 11.1.0 to 11.1.5
From 11.2.0 to 11.2.6
From 12.0.0 to 12.0.3
From 12.1.0 to 12.1.4
Version 13.0.0

References (2)

Source: PSIRT@rockwellautomation.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.