Lucene search

K
zdiRgodZDI-22-1302
HistorySep 28, 2022 - 12:00 a.m.

Rockwell Automation ThinManager ThinServer URI Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

2022-09-2800:00:00
rgod
www.zerodayinitiative.com
10
remote code execution
authentication bypass
https traffic parsing

EPSS

0.002

Percentile

57.4%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation ThinManager. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of HTTPS traffic. When parsing a URI, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the web service.

EPSS

0.002

Percentile

57.4%

Related for ZDI-22-1302