CVE-2023-27855
Published Mar 22, 2023
Last updated a year ago
Overview
- Description
- In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could overwrite existing executable files with attacker-controlled, malicious contents, potentially causing remote code execution.
- Source
- PSIRT@rockwellautomation.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B3690F79-0AB9-4FBA-BCF0-BCCCF00EFD31", "versionEndIncluding": "10.0.2", "versionStartIncluding": "6.0.0" }, { "criteria": "cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "68D1B6ED-F052-4CAC-80B0-614AF4FA5455", "versionEndIncluding": "11.0.5", "versionStartIncluding": "11.0.0" }, { "criteria": "cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8066DE9-ACFA-42F9-AC88-08FB8ACC745E", "versionEndIncluding": "11.1.5", "versionStartIncluding": "11.1.0" }, { "criteria": "cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ADF30A13-51AD-479B-B0C4-462C059D511B", "versionEndIncluding": "11.2.6", "versionStartIncluding": "11.2.0" }, { "criteria": "cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A809366-5838-445A-8034-787551292BA7", "versionEndIncluding": "12.0.4", "versionStartIncluding": "12.0.0" }, { "criteria": "cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EDC56DD9-44E6-45C0-82F1-0D9EAA2343BC", "versionEndIncluding": "12.1.5", "versionStartIncluding": "12.1.0" }, { "criteria": "cpe:2.3:a:rockwellautomation:thinmanager:13.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D7FA8090-F7EB-4C5D-AD9D-7D82F34F34D1" }, { "criteria": "cpe:2.3:a:rockwellautomation:thinmanager:13.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0486F851-53AC-41C5-9ECE-1EA2DB1D3FAC" } ], "operator": "OR" } ] } ]