CVE-2023-27856: Rockwellautomation Thinmanager

High severity, CVSS 7.5. EPSS: 77.2% chance of exploitation in the next 30 days.

In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.

Affected products

  • Rockwellautomation Thinmanager: from 6.0.0, up to and including 10.0.2; from 11.0.0, up to and including 11.0.5; from 11.1.0, up to and including 11.1.5; from 11.2.0, up to and including 11.2.6; from 12.0.0, up to and including 12.0.4; from 12.1.0, up to and including 12.1.5; …

Published 2023-03-22. Last modified 2026-06-17.