CVE-2023-27856
22.03.2023, 00:15
In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.
Vendor | Product | Version |
---|---|---|
rockwellautomation | thinmanager | 6.0.0 ≤ 𝑥 ≤ 10.0.2 |
rockwellautomation | thinmanager | 11.0.0 ≤ 𝑥 ≤ 11.0.5 |
rockwellautomation | thinmanager | 11.1.0 ≤ 𝑥 ≤ 11.1.5 |
rockwellautomation | thinmanager | 11.2.0 ≤ 𝑥 ≤ 11.2.6 |
rockwellautomation | thinmanager | 12.0.0 ≤ 𝑥 ≤ 12.0.4 |
rockwellautomation | thinmanager | 12.1.0 ≤ 𝑥 ≤ 12.1.5 |
rockwellautomation | thinmanager | 13.0.0 |
rockwellautomation | thinmanager | 13.0.1 |
𝑥
= Vulnerable software versions