CVE-2023-27857
high · 7.5In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation.
7.5
CVSS
18.3%
EPSS (exploit prob.)
97th
EPSS percentile
2023-03-22
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-125
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| rockwellautomation | thinmanager | >= 11.0.0, < 11.0.5 |
| rockwellautomation | thinmanager | >= 11.1.0, < 11.1.5 |
| rockwellautomation | thinmanager | >= 11.2.0, < 11.2.6 |
| rockwellautomation | thinmanager | >= 12.0.0, < 12.0.3 |
| rockwellautomation | thinmanager | >= 12.1.0, < 12.1.4 |
| rockwellautomation | thinmanager | 13.0.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-27857