Security Advisory

CVE-2023-27856

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-03-21 23:55:23
Last updated 2025-02-25 21:22:03
Assigner Rockwell
State PUBLISHED

Description

In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automations ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.