CVE-2023-27857

EUVD-2023-31592
 In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field



 in Rockwell Automation's ThinManager ThinServer.  An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation.



 

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
RockwellCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
rockwellautomationthinmanager
11.0.0 ≤
𝑥
< 11.0.5
rockwellautomationthinmanager
11.1.0 ≤
𝑥
< 11.1.5
rockwellautomationthinmanager
11.2.0 ≤
𝑥
< 11.2.6
rockwellautomationthinmanager
12.0.0 ≤
𝑥
< 12.0.3
rockwellautomationthinmanager
12.1.0 ≤
𝑥
< 12.1.4
rockwellautomationthinmanager
13.0.0
𝑥
= Vulnerable software versions