PoC Index

CVE-2023-27856

HIGH 7.5EPSS 77.2%

In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
77.22% chance of exploitation in the next 30 days, 100th percentile
Published
2023-03-21
Updated
2025-02-25

Metasploit modules (1)

References

Related