HTTP: Rockwell Automation ThinManager ThinServer URI Heap Buffer Overflow

This signature detects attempts to exploit a known vulnerability against Rockwell Automation ThinManager ThinServer. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the web service.

Extended Description

Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifically crafted TFTP or HTTPS request, causing a heap-based buffer overflow that crashes the ThinServer process. If successfully exploited, this could expose the server to arbitrary remote code execution.

Affected Products

Rockwellautomation thinmanager

Short Name
HTTP:OVERFLOW:ROCKWELL-THINMNGR
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Automation Buffer CVE-2022-38742 Heap Overflow Rockwell ThinManager ThinServer URI
Release Date
05/18/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3599
False Positive
Unknown
Vendors

Rockwellautomation

Found a potential security threat?