peter bassill · operator
$ cve CVE-2023-27855 JSON

CVE-2023-27855

9.8
CRITICAL · CVSS 3.1 · EPSS 13.5% (pctl 96)

Patch early

EPSS 13.5% — above the 10% action threshold.

Description

In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could overwrite existing executable files with attacker-controlled, malicious contents, potentially causing remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS13.45% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploitnone known
Published2023-03-22
Last modified2026-06-17

Affected (1)

VendorProduct
rockwellautomationthinmanager

References

→ the Explorer  ·  watch your stack  ·  NVD