Rockwell Automation ThinManager product allows the use of medium strength ciphers. If the client requests an insecure cipher, a malicious actor could potentially decrypt traffic sent between the client and server API.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2023-33928 | Rockwell Automation ThinManager product allows the use of medium strength ciphers. If the client requests an insecure cipher, a malicious actor could potentially decrypt traffic sent between the client and server API. |
Fixes
Solution
Customers should upgrade to 13.0.2 to correct this issue. If upgrading is not possible, customers should ensure that the 3DES encryption algorithm is not used.
Workaround
No workaround given by the vendor.
References
History
Fri, 24 Jan 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2025-01-24T21:16:26.466Z
Reserved: 2023-05-01T13:52:27.487Z
Link: CVE-2023-2443

Updated: 2024-08-02T06:26:09.005Z

Status : Modified
Published: 2023-05-11T19:15:09.377
Modified: 2024-11-21T07:58:37.627
Link: CVE-2023-2443

No data.

No data.