Rockwell Automation ThinManager ThinServer Path Traversal Upload
CVE-2023-27855
Key Information:
- Vendor
Rockwell Automation
- Status
- Vendor
- CVE Published:
- 22 March 2023
What is CVE-2023-27855?
In specific versions of Rockwell Automation's ThinManager ThinServer, a pathway traversal vulnerability has been identified. This flaw permits unauthorized remote attackers to exploit the system by uploading malicious files to any location on the disk drive where ThinServer.exe is situated. Such an exploit could allow attackers to overwrite legitimate executable files with harmful content, raising the prospect of remote code execution.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ThinManager ThinServer 6.x - 10.x
ThinManager ThinServer 11.0.0 - 11.0.5
ThinManager ThinServer 11.1.0 - 11.1.5
References
EPSS Score
62% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved