CVE-2023-2914 HIGH

CVE-2023-2914: Rockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerabilitiy

Vendor Rockwell Automation
Product ThinManager ThinServer
Weakness CWE-20 · Input validation
Published August 17, 2023
Last update October 8, 2024

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products. When the ThinManager processes incoming messages, a read access violation occurs and terminates the process. A malicious user could exploit this vulnerability by sending a crafted synchronization protocol message and causing a denial of service condition in the software.

Key dates

02Disclosure timeline

August 17, 2023 CVE published
October 8, 2024 Record updated