PT-2023-4445 · Rockwell Automation · Thinmanager

Published

2023-08-17

·

Updated

2025-06-09

·

CVE-2023-2917

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Rockwell Automation ThinManager ThinServer (affected versions not specified)
Description The issue exists due to insufficient input validation in the ThinServer component of the Rockwell Automation ThinManager platform. This allows a remote attacker to potentially execute arbitrary code by exploiting the vulnerability. Specifically, a path traversal vulnerability exists via the filename field when the ThinManager processes a certain function, enabling an unauthenticated remote attacker to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. Exploitation can occur through sending a crafted synchronization protocol message, potentially leading to remote code execution abilities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2023-04836
CVE-2023-2917

Affected Products

Thinmanager