TCP: Rockwell Automation Thinmanager Thinserver Heap Buffer Overflow

This signature detects attempts to exploit a known vulnerability against Rockwell Automation Thinmanager Thinserver. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the Rockwell Automation Thinmanager Thinserver.

Extended Description

In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's ThinManager ThinServer.An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation.

Affected Products

Rockwellautomation thinmanager

References

CVE: CVE-2023-27857

Short Name
TCP:C2S:RCKWLL-AUMTN-THNMGR-BO
Severity
Major
Recommended
False
Recommended Action
Drop
Category
TCP
Keywords
Automation Buffer CVE-2023-27857 Heap Overflow Rockwell Thinmanager Thinserver
Release Date
07/06/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3646
Port
TCP/2031
False Positive
Unknown
Vendors

Rockwellautomation

Found a potential security threat?