CVE-2023-27855

CRITICAL

ThinManager Path Traversal (CVE-2023-27855) Arbitrary File Upload

Title source: metasploit

Description

In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could overwrite existing executable files with attacker-controlled, malicious contents, potentially causing remote code execution.

Exploits (1)

metasploit WORKING POC
by Michael Heinzl, Tenable · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/networking/thinmanager_traversal_upload.rb

Scores

CVSS v3 9.8
EPSS 0.7401
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (3)
rockwellautomation/thinmanager 13.0.0
rockwellautomation/thinmanager 13.0.1
rockwellautomation/thinmanager 6.0.0 - 10.0.2
Published Mar 22, 2023
Tracked Since Feb 18, 2026