CVE-2023-2915 is a critical path traversal vulnerability affecting Rockwell Automation ThinManager Thinserver. This flaw, stemming from improper input validation, allows an unauthenticated remote attacker to delete arbitrary files with system privileges, potentially leading to a denial-of-service condition. With a CVSS score of 9.1 (CRITICAL) and a FAUCET Risk Score of 96/100, the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, resulting in high impact to integrity and availability. While not currently on CISA's KEV catalog, a Metasploit module exists for arbitrary file deletion, and it has garnered significant community discussion and media coverage, indicating active awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0.0, <= 11.0.6CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:* | ||
>= 11.1.0, <= 11.1.6CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:* | ||
>= 11.2.0, <= 11.2.7CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:* | ||
>= 12.0.0, <= 12.0.5CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:* | ||
>= 12.1.0, <= 12.1.6CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Rockwell Automation ThinManager ThinServer Multiple Vulnerabilities
Aug 17, 2023Rockwell Automation ThinManager ThinServer Multiple Vulnerabilities
Aug 17, 2023Rockwell Automation ThinManager ThinServer Multiple Vulnerabilities
Aug 17, 2023Rockwell Automation ThinManager ThinServer Multiple Vulnerabilities
Aug 17, 2023Multiple Vulnerabilities in ThinManager® ThinServer™