In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.
2023-03-22T00:15:12.810
2024-11-21T07:53:35.160
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | rockwellautomation | thinmanager | ≤ 10.0.2 | Yes |
Application | rockwellautomation | thinmanager | ≤ 11.0.5 | Yes |
Application | rockwellautomation | thinmanager | ≤ 11.1.5 | Yes |
Application | rockwellautomation | thinmanager | ≤ 11.2.6 | Yes |
Application | rockwellautomation | thinmanager | ≤ 12.0.4 | Yes |
Application | rockwellautomation | thinmanager | ≤ 12.1.5 | Yes |
Application | rockwellautomation | thinmanager | 13.0.0 | Yes |
Application | rockwellautomation | thinmanager | 13.0.1 | Yes |