High severity7.5NVD Advisory· Published Mar 22, 2023· Updated Jun 17, 2026
CVE-2023-27856
CVE-2023-27856
Description
In affected versions, path traversal exists when processing a message of type 8
in Rockwell Automation's ThinManager ThinServer.
An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*range: >=6.0.0,<=10.0.2
- cpe:2.3:a:rockwellautomation:thinmanager:13.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:rockwellautomation:thinmanager:13.0.1:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 6.x - 10.x
Patches
Vulnerability mechanics
References
1- rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1138640nvdPermissions RequiredVendor Advisory
News mentions
0No linked articles in our index yet.