CVE-2023-27855
CRITICALThinManager Path Traversal (CVE-2023-27855) Arbitrary File Upload
Title source: metasploitDescription
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could overwrite existing executable files with attacker-controlled, malicious contents, potentially causing remote code execution.
Exploits (1)
metasploit
WORKING POC
by Michael Heinzl, Tenable · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/networking/thinmanager_traversal_upload.rb
Scores
CVSS v3
9.8
EPSS
0.7401
EPSS Percentile
98.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-22
Status
published
Products (3)
rockwellautomation/thinmanager
13.0.0
rockwellautomation/thinmanager
13.0.1
rockwellautomation/thinmanager
6.0.0 - 10.0.2
Published
Mar 22, 2023
Tracked Since
Feb 18, 2026