CVE-2023-27856
high · 7.5In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.
7.5
CVSS
77.2%
EPSS (exploit prob.)
100th
EPSS percentile
2023-03-22
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| rockwellautomation | thinmanager | >= 6.0.0, <= 10.0.2 |
| rockwellautomation | thinmanager | >= 11.0.0, <= 11.0.5 |
| rockwellautomation | thinmanager | >= 11.1.0, <= 11.1.5 |
| rockwellautomation | thinmanager | >= 11.2.0, <= 11.2.6 |
| rockwellautomation | thinmanager | >= 12.0.0, <= 12.0.4 |
| rockwellautomation | thinmanager | >= 12.1.0, <= 12.1.5 |
| rockwellautomation | thinmanager | 13.0.0 |
| rockwellautomation | thinmanager | 13.0.1 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-27856