CVE-2023-27857

 In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field



 in Rockwell Automation's ThinManager ThinServer.An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation.



 

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
RockwellCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
rockwellautomationthinmanager
11.0.0 ≤
𝑥
< 11.0.5
rockwellautomationthinmanager
11.1.0 ≤
𝑥
< 11.1.5
rockwellautomationthinmanager
11.2.0 ≤
𝑥
< 11.2.6
rockwellautomationthinmanager
12.0.0 ≤
𝑥
< 12.0.3
rockwellautomationthinmanager
12.1.0 ≤
𝑥
< 12.1.4
rockwellautomationthinmanager
13.0.0
𝑥
= Vulnerable software versions