Impact
The vulnerability is a path traversal flaw in Rockwell Automation FactoryTalk ThinManager. Improper validation of file paths within the API allows an authenticated user to write files to directories outside of the intended application folder. The write operation can target restricted system directories, enabling placement of arbitrary files that may alter system configuration or interfere with application behavior.
Affected Systems
The vulnerability affects Rockwell Automation FactoryTalk ThinManager. No specific product versions are listed in the advisory, so all deployments of this software should be considered potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.2 indicates a high impact potential, while the EPSS score of less than 1% suggests a low probability of exploitation in the near term. The vulnerability is not listed in CISA's KEV catalog. An attacker must authenticate to the service in order to reach the vulnerable file-write operation, but once authenticated the flaw removes directory boundaries, enabling arbitrary file placement in restricted directories.
OpenCVE Enrichment