CVE-2023-2917
About
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function. If exploited, an unauthenticated remote attacker can upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. A malicious user could exploit this vulnerability by sending a crafted synchronization protocol message and potentially gain remote code execution abilities.
Rainforest analyst review
Rockwell Automation ThinManager ThinServer fails to validate input on a filename field, producing a path traversal that lets an unauthenticated remote attacker upload arbitrary files to any directory on the drive where ThinServer.exe runs. The advisory notes that a crafted synchronization-protocol message can drive this and that it may escalate to remote code execution, so an unauthenticated file-write primitive here is a plausible path to full control of the host.
ThinManager sits in industrial and operational environments managing thin clients, which raises the stakes: an unauthenticated write-anywhere bug that can lead to RCE on such a server is the kind of thing ICS-focused advisories flag prominently and that both opportunistic and targeted actors act on. The lack of any authentication or user-interaction requirement means the only real barrier is network reachability of the ThinServer synchronization protocol.
So exposure and segmentation lead our response. We would determine which ThinServer instances are reachable, ensure the synchronization protocol is confined to trusted management networks rather than exposed broadly, and prioritize the vendor update on anything internet- or IT-reachable. Where OT change windows constrain patching, restricting who can send that protocol message to the server is the interim control that removes the unauthenticated path.
References
Related CVEs
Frequently asked questions
What is CVE-2023-2917?
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function. If exploited, an unauthenticated remote attacker can upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed.
How severe is CVE-2023-2917?
CVE-2023-2917 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2023-2917 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2023-2917?
Public advisories list the following as affected: thinmanager thinserver. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2023-2917?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
