Aller au contenu

Fiche vulnérabilité

CVE-2023-27856 : faille élevée rockwellautomation thinmanager (CVSS 7.5)

Description

In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
22 mars 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • rockwellautomation thinmanager

Références

Rechercher une autre vulnérabilité dans la base CVE