CRITICAL

CVE-2023-2917

CVSS v3

9.8

CRITICAL

EPSS Score

40.7%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability.  Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function. If exploited, an unauthenticated remote attacker can upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed.  A malicious user could exploit this vulnerability by sending a crafted synchronization protocol message and potentially gain remote code execution abilities.

Technical details

Published
8/17/2023

Frequently asked questions

What is CVE-2023-2917?

The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability.  Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function. If exploited, an unauthenticated remote attacker can upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed.  A malicious user could exploit this vulnerability by sending a crafted synchronization protocol message and potentially gain remote code execution abilities.

Is CVE-2023-2917 actively exploited?

Active exploitation of CVE-2023-2917 has not been confirmed. The EPSS score is 40.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-2917?

CVE-2023-2917 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-2917 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.