← Vulnerability feed

Vulnerability record · CVE-2023-27857 · published 22 March 2023

CVE-2023-27857: Rockwellautomation thinmanager out-of-bounds read vulnerability

Rockwellautomation · Thinmanager

In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's ThinManager ThinServer.  An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation.

7.5 CVSS 3.1 High EPSS 18% · top 2.9% CWE-125 · Out-of-bounds read
7.5CVSS 3.1 base score
18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's ThinManager ThinServer.  An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-27857 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27855Rockwellautomation thinmanager path traversal vulnerabilityIn affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote at…EPSS 13%9.8CVE-2022-38742Rockwellautomation thinmanager heap-based buffer overflow vulnerabilityRockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifica…EPSS 22%9.3CVE-2024-10386Rockwellautomation thinmanager missing authentication for critical function vulnerabilityCVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network acces…EPSS 19%9.3CVE-2024-5989Rockwellautomation thinmanager improper input validation vulnerabilityDue to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause …EPSS 2.4%9.3CVE-2024-5988Rockwellautomation thinmanager improper input validation vulnerabilityDue to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a …EPSS 2.7%8.7CVE-2024-10387Rockwellautomation thinmanager out-of-bounds read vulnerabilityCVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow a threat actor with network acc…EPSS 8.0%8.7CVE-2024-5990Rockwellautomation thinmanager improper input validation vulnerabilityDue to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation Thin…EPSS 2.3%8.6CVE-2025-9065Rockwellautomation thinmanager server-side request forgery (ssrf) vulnerabilityA server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authentic…EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2023-27857), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.