Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-2913

Опубликовано: 18 июл. 2023
Источник: nvd
CVSS3: 7.5
CVSS3: 6.5
EPSS Низкий

Описание

An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This feature is disabled by default. When the API is enabled and handling requests, a path traversal vulnerability exists that allows a remote actor to leverage the privileges of the server’s file system and read arbitrary files stored in it. A malicious user could exploit this vulnerability by executing a path that contains manipulating variables.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*
Версия от 13.0.0 (включая) до 13.0.2 (включая)

EPSS

Процентиль: 14%
0.00047
Низкий

7.5 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-23
CWE-22

Связанные уязвимости

CVSS3: 7.5
github
больше 2 лет назад

An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This feature is disabled by default. When the API is enabled and handling requests, a path traversal vulnerability exists that allows a remote actor to leverage the privileges of the server’s file system and read arbitrary files stored in it. A malicious user could exploit this vulnerability by executing a path that contains manipulating variables.

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость конфигурации Enable API Endpoints компонента ThinServer платформы для централизованного управления приложениями Rockwell Automation ThinManager, позволяющая нарушителю читать произвольные файлы

EPSS

Процентиль: 14%
0.00047
Низкий

7.5 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-23
CWE-22