CVE-2023-27855 Information
Mar 23, 2023
cve
Description
In affected versions a path traversal exists when processing a message in Rockwell Automation’s ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could overwrite existing executable files with attacker-controlled malicious contents potentially causing remote code execution.
Reference
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1138640
Share on: