Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.
Metrics
Affected Vendors & Products
References
History
Mon, 16 Sep 2024 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Rockwellautomation
Rockwellautomation thinmanager Rockwellautomation thinserver |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:* cpe:2.3:a:rockwellautomation:thinserver:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Rockwellautomation
Rockwellautomation thinmanager Rockwellautomation thinserver |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Rockwell
Published: 2024-06-25T16:01:39.103Z
Updated: 2024-08-01T21:25:03.287Z
Reserved: 2024-06-13T20:56:09.876Z
Link: CVE-2024-5989
Vulnrichment
Updated: 2024-08-01T21:25:03.287Z
NVD
Status : Modified
Published: 2024-06-25T16:15:25.363
Modified: 2024-11-21T09:48:42.330
Link: CVE-2024-5989
Redhat
No data.