← Vulnerability feed

Vulnerability record · CVE-2023-27856 · published 22 March 2023

CVE-2023-27856: Rockwell ThinManager ThinServer path traversal in message type 8

Rockwellautomation · Thinmanager

ThinManager ThinServer contains a path traversal flaw (CWE-22) triggered when it processes a message of type 8. An unauthenticated remote attacker can use it to download arbitrary files from the disk drive where ThinServer.exe is installed. Because the service is reachable over the network with no credentials required, exposed ThinServer instances are directly at risk of file disclosure.

7.5 CVSS 3.1 High EPSS 77% · top 0.5% CWE-22 · Path traversal
7.5CVSS 3.1 base score
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote file disclosure with a high CVSS score and very high EPSS, though no KEV listing or confirmed in-the-wild exploitation is present.

What it is

ThinManager ThinServer contains a path traversal flaw (CWE-22) triggered when it processes a message of type 8. An unauthenticated remote attacker can use it to download arbitrary files from the disk drive where ThinServer.exe is installed. Because the service is reachable over the network with no credentials required, exposed ThinServer instances are directly at risk of file disclosure.

Impact

An attacker gains read access to arbitrary files on the ThinServer installation drive, which can expose configuration data, credentials or other sensitive files. There is no integrity or availability impact per the CVSS vector; the loss is confidentiality only.

Attack surface

Reachable over the network via a crafted message of type 8 sent to the ThinServer service; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication and no user interaction are needed. The record does not specify which port or protocol carries the message.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.77225 probability, 0.9953 percentile), indicating a strong likelihood of attempted exploitation, but the record contains no public exploit or in-the-wild confirmation.

What to do

  • Apply the Rockwell Automation fix referenced in advisory a_id/1138640; treat patching as the first action.
  • Restrict network access to ThinServer so only trusted management hosts can reach it, using firewall rules or segmentation.
  • Do not expose ThinServer directly to untrusted networks or the internet.
  • Monitor the vendor advisory for updated affected-version and workaround guidance, since the record does not list affected versions.
  • Review file system permissions on the ThinServer drive to limit what a successful traversal could read.

Detection

  • Alert on unexpected message type 8 traffic to ThinServer hosts and baseline normal message-type usage.
  • Monitor ThinServer process file reads for paths containing traversal sequences (../) or access to files outside expected directories.
  • Watch for anomalous outbound transfers or repeated file-read activity from ThinServer hosts.
  • Correlate ThinServer access logs with source IPs that are not known management stations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-27856 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27855Rockwellautomation thinmanager path traversal vulnerabilityIn affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote at…EPSS 13%9.8CVE-2022-38742Rockwellautomation thinmanager heap-based buffer overflow vulnerabilityRockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifica…EPSS 22%9.3CVE-2024-10386Rockwellautomation thinmanager missing authentication for critical function vulnerabilityCVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network acces…EPSS 19%9.3CVE-2024-5989Rockwellautomation thinmanager improper input validation vulnerabilityDue to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause …EPSS 2.4%9.3CVE-2024-5988Rockwellautomation thinmanager improper input validation vulnerabilityDue to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a …EPSS 2.7%8.7CVE-2024-10387Rockwellautomation thinmanager out-of-bounds read vulnerabilityCVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow a threat actor with network acc…EPSS 8.0%8.7CVE-2024-5990Rockwellautomation thinmanager improper input validation vulnerabilityDue to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation Thin…EPSS 2.3%8.6CVE-2025-9065Rockwellautomation thinmanager server-side request forgery (ssrf) vulnerabilityA server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authentic…EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2023-27856), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.