CVE-2023-27855
Last modified
CVE-2023-27855 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. EPSS estimates a 13.45% chance of exploitation in the next 30 days.
Description
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could overwrite existing executable files with attacker-controlled, malicious contents, potentially causing remote code execution.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Thinmanager | >= 6.0.0, <= 10.0.2 |
| Rockwellautomation | Thinmanager | >= 11.0.0, <= 11.0.5 |
| Rockwellautomation | Thinmanager | >= 11.1.0, <= 11.1.5 |
| Rockwellautomation | Thinmanager | >= 11.2.0, <= 11.2.6 |
| Rockwellautomation | Thinmanager | >= 12.0.0, <= 12.0.4 |
| Rockwellautomation | Thinmanager | >= 12.1.0, <= 12.1.5 |
| Rockwellautomation | Thinmanager | 13.0.0 |
| Rockwellautomation | Thinmanager | 13.0.1 |
References
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1138640Permissions Required, Vendor Advisory
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1138640Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-27855?
How severe is CVE-2023-27855?
How do I fix CVE-2023-27855?
Are you affected by CVE-2023-27855?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
