A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that points to the target directory.
Metrics
Affected Vendors & Products
References
History
Wed, 28 Aug 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 23 Aug 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that points to the target directory. | |
Title | Rockwell Automation ThinManager® ThinServer™ Information Disclosure | |
Weaknesses | CWE-732 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: Rockwell
Published: 2024-08-23T11:51:55.080Z
Updated: 2024-08-28T16:21:02.832Z
Reserved: 2024-08-19T20:06:24.873Z
Link: CVE-2024-7986
Vulnrichment
Updated: 2024-08-28T16:20:59.124Z
NVD
Status : Awaiting Analysis
Published: 2024-08-23T12:15:03.920
Modified: 2024-08-23T16:18:28.547
Link: CVE-2024-7986
Redhat
No data.