CVE-2023-2915: Rockwellautomation Thinmanager Thinserver
Critical severity, CVSS 9.1. EPSS: 81.8% chance of exploitation in the next 30 days.
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists when the ThinManager software processes a certain function. If exploited, an unauthenticated remote threat actor can delete arbitrary files with system privileges. A malicious user could exploit this vulnerability by sending a specifically crafted synchronization protocol message resulting in a denial-of-service condition.
Affected products
- Rockwellautomation Thinmanager Thinserver: from 11.0.0, up to and including 11.0.6; from 11.1.0, up to and including 11.1.6; from 11.2.0, up to and including 11.2.7; from 12.0.0, up to and including 12.0.5; from 12.1.0, up to and including 12.1.6; from 13.0.0, up to and including 13.0.2; …
Published 2023-08-17. Last modified 2026-06-17.