« Volver al listado

CVE-2023-2914

Estado: ModificadaAlta (7.5)—

The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products. When the ThinManager processes incoming messages, a read access violation occurs and terminates the process. A malicious user could exploit this vulnerability by sending a crafted synchronization protocol message and causing a denial of service condition in the software.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-2914",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-2914",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-08T17:05:51.847648Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "PSIRT@rockwellautomation.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "PSIRT@rockwellautomation.com",
      "affectedData": [
        {
          "vendor": "Rockwell Automation",
          "product": "ThinManager ThinServer",
          "versions": [
            {
              "status": "affected",
              "version": "11.0.0 - 11.2.6"
            },
            {
              "status": "affected",
              "version": "11.1.0 - 11.1.6"
            },
            {
              "status": "affected",
              "version": "11.2.0 - 11.2.7"
            },
            {
              "status": "affected",
              "version": "12.0.0 - 12.0.5"
            },
            {
              "status": "affected",
              "version": "12.1.0 - 12.1.6"
            },
            {
              "status": "affected",
              "version": "13.0.0 - 13.0.2"
            },
            {
              "status": "affected",
              "version": "13.1.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*"
          ],
          "vendor": "rockwellautomation",
          "product": "thinmanager_thinserver",
          "versions": [
            {
              "status": "affected",
              "version": "11.0.0 - 11.2.6"
            },
            {
              "status": "affected",
              "version": "11.1.0 - 11.1.6"
            },
            {
              "status": "affected",
              "version": "11.2.0 - 11.2.7"
            },
            {
              "status": "affected",
              "version": "12.0.0 - 12.0.5"
            },
            {
              "status": "affected",
              "version": "12.1.0 - 12.1.6"
            },
            {
              "status": "affected",
              "version": "13.0.0 - 13.0.2"
            },
            {
              "status": "affected",
              "version": "13.1.0"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-08-17T16:15:09.513",
  "references": [
    {
      "url": "https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1140471",
      "tags": [
        "Permissions Required"
      ],
      "source": "PSIRT@rockwellautomation.com"
    },
    {
      "url": "https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1140471",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "PSIRT@rockwellautomation.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-190"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products. When the ThinManager processes incoming messages, a read access violation occurs and terminates the process. A malicious user could exploit this vulnerability by sending a crafted synchronization protocol message and causing a denial of service condition in the software.  "
    }
  ],
  "lastModified": "2026-06-17T05:53:46.590",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C40EF89-902D-40A0-9460-9C2037CDAF45",
              "versionEndIncluding": "11.0.6",
              "versionStartIncluding": "11.0.0"
            },
            {
              "criteria": "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCB9F021-2307-4183-A6B8-CAEE88808C92",
              "versionEndIncluding": "11.1.6",
              "versionStartIncluding": "11.1.0"
            },
            {
              "criteria": "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8C2E2BF-3ABA-4E69-9A8F-4E2AC6C48E2E",
              "versionEndIncluding": "11.2.7",
              "versionStartIncluding": "11.2.0"
            },
            {
              "criteria": "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66054D47-416A-4194-9B95-AE810924AD94",
              "versionEndIncluding": "12.0.5",
              "versionStartIncluding": "12.0.0"
            },
            {
              "criteria": "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AAE89B3-6C25-4DE7-898A-2F8637122B01",
              "versionEndIncluding": "12.1.6",
              "versionStartIncluding": "12.1.0"
            },
            {
              "criteria": "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5D9F5DA-D66A-4F88-A1C4-E1411715162F",
              "versionEndIncluding": "13.0.2",
              "versionStartIncluding": "13.0.0"
            },
            {
              "criteria": "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:13.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE7FC8D4-F5EF-45DC-9D95-4CFBC3FE1E3B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "PSIRT@rockwellautomation.com"
}