A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten.
History

Mon, 26 Aug 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation thinmanager Thinserver
CPEs cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*
Vendors & Products Rockwellautomation
Rockwellautomation thinmanager Thinserver
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 26 Aug 2024 15:00:00 +0000

Type Values Removed Values Added
Description A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten.
Title ThinManager® ThinServer™ Information Disclosure and Remote Code Execution Vulnerabilities
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published: 2024-08-26T14:47:07.612Z

Updated: 2024-08-26T17:46:47.107Z

Reserved: 2024-08-19T20:06:27.545Z

Link: CVE-2024-7988

cve-icon Vulnrichment

Updated: 2024-08-26T17:46:38.593Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-26T15:15:09.140

Modified: 2024-08-26T18:35:14.617

Link: CVE-2024-7988

cve-icon Redhat

No data.