Security Advisory

CVE-2023-27856

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-03-21 23:55:23
Last updated 2025-02-25 21:22:03
Assigner Rockwell
CVSS score 7.5
State PUBLISHED

Description

In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.