Critical severity9.8NVD Advisory· Published Mar 22, 2023· Updated Jun 17, 2026
CVE-2023-27855
CVE-2023-27855
Description
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could overwrite existing executable files with attacker-controlled, malicious contents, potentially causing remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*range: >=6.0.0,<=10.0.2
- cpe:2.3:a:rockwellautomation:thinmanager:13.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:rockwellautomation:thinmanager:13.0.1:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 6.x - 10.x
Patches
Vulnerability mechanics
References
1- rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1138640nvdPermissions RequiredVendor Advisory
News mentions
0No linked articles in our index yet.