Vulnerability record · CVE-2023-27856 · published 22 March 2023
CVE-2023-27856: Rockwell ThinManager ThinServer path traversal in message type 8
Rockwellautomation · Thinmanager
ThinManager ThinServer contains a path traversal flaw (CWE-22) triggered when it processes a message of type 8. An unauthenticated remote attacker can use it to download arbitrary files from the disk drive where ThinServer.exe is installed. Because the service is reachable over the network with no credentials required, exposed ThinServer instances are directly at risk of file disclosure.
Description
In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote file disclosure with a high CVSS score and very high EPSS, though no KEV listing or confirmed in-the-wild exploitation is present.
What it is
ThinManager ThinServer contains a path traversal flaw (CWE-22) triggered when it processes a message of type 8. An unauthenticated remote attacker can use it to download arbitrary files from the disk drive where ThinServer.exe is installed. Because the service is reachable over the network with no credentials required, exposed ThinServer instances are directly at risk of file disclosure.
Impact
An attacker gains read access to arbitrary files on the ThinServer installation drive, which can expose configuration data, credentials or other sensitive files. There is no integrity or availability impact per the CVSS vector; the loss is confidentiality only.
Attack surface
Reachable over the network via a crafted message of type 8 sent to the ThinServer service; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication and no user interaction are needed. The record does not specify which port or protocol carries the message.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.77225 probability, 0.9953 percentile), indicating a strong likelihood of attempted exploitation, but the record contains no public exploit or in-the-wild confirmation.
What to do
- Apply the Rockwell Automation fix referenced in advisory a_id/1138640; treat patching as the first action.
- Restrict network access to ThinServer so only trusted management hosts can reach it, using firewall rules or segmentation.
- Do not expose ThinServer directly to untrusted networks or the internet.
- Monitor the vendor advisory for updated affected-version and workaround guidance, since the record does not list affected versions.
- Review file system permissions on the ThinServer drive to limit what a successful traversal could read.
Detection
- Alert on unexpected message type 8 traffic to ThinServer hosts and baseline normal message-type usage.
- Monitor ThinServer process file reads for paths containing traversal sequences (../) or access to files outside expected directories.
- Watch for anomalous outbound transfers or repeated file-read activity from ThinServer hosts.
- Correlate ThinServer access logs with source IPs that are not known management stations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1138640 | Permissions RequiredVendor Advisory |
| https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1138640 | Permissions RequiredVendor Advisory |
Track CVE-2023-27856 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-27856), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.