CVE-2023-2915 is a critical improper input validation vulnerability in Rockwell Automation ThinManager ThinServer. The flaw exists in the processing of a specific synchronization protocol message (message type 21), where insufficient validation of user-supplied input allows for path traversal. An unauthenticated remote attacker can exploit this to delete arbitrary files on the system with SYSTEM privileges by sending a specially crafted message to the ThinServer component. This can result in a denial-of-service condition or further compromise of the system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit auxiliary module targeting a path traversal vulnerability (CVE-2023-2915) in Rockwell Automation ThinManager (versions <= 13.1.0). The exploit allows an attacker to delete arbitrary files on the target system with SYSTEM privileges by sending a specially crafted TCP message to the ThinManager service, which listens on port 2031 by default. The module is written in Ruby and is structured according to Metasploit conventions, with options to specify the file to delete and the traversal depth. The exploit is operational and can be used to remove any file accessible to the ThinManager service, potentially leading to denial of service or further compromise. No hardcoded IPs or domains are present; the attacker supplies the target address and file path.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.