In affected versions, path traversal exists when processing a message of type 8
in Rockwell Automation's ThinManager ThinServer.
An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Customers are directed to update to versions of the product that correct the vulnerability as listed in the reference article.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Feb 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2025-02-25T21:22:03.982Z
Reserved: 2023-03-06T18:21:21.067Z
Link: CVE-2023-27856
Updated: 2024-08-02T12:23:30.592Z
Status : Modified
Published: 2023-03-22T00:15:12.810
Modified: 2024-11-21T07:53:35.160
Link: CVE-2023-27856
No data.
OpenCVE Enrichment
No data.