CVE-2023-2917: Rockwellautomation Thinmanager Thinserver
Critical severity, CVSS 9.8. EPSS: 72.2% chance of exploitation in the next 30 days.
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function. If exploited, an unauthenticated remote attacker can upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. A malicious user could exploit this vulnerability by sending a crafted synchronization protocol message and potentially gain remote code execution abilities.
Affected products
- Rockwellautomation Thinmanager Thinserver: from 11.0.0, up to and including 11.0.6; from 11.1.0, up to and including 11.1.6; from 11.2.0, up to and including 11.2.7; from 12.0.0, up to and including 12.0.5; from 12.1.0, up to and including 12.1.6; from 13.0.0, up to and including 13.0.2; …
Published 2023-08-17. Last modified 2026-06-17.