The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products. When the ThinManager processes incoming messages, a read access violation occurs and terminates the process. A malicious user could exploit this vulnerability by sending a crafted synchronization protocol message and causing a denial of service condition in the software.
2023-08-17T16:15:09.513
2024-11-21T07:59:33.587
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | rockwellautomation | thinmanager_thinserver | ≤ 11.0.6 | Yes |
Application | rockwellautomation | thinmanager_thinserver | ≤ 11.1.6 | Yes |
Application | rockwellautomation | thinmanager_thinserver | ≤ 11.2.7 | Yes |
Application | rockwellautomation | thinmanager_thinserver | ≤ 12.0.5 | Yes |
Application | rockwellautomation | thinmanager_thinserver | ≤ 12.1.6 | Yes |
Application | rockwellautomation | thinmanager_thinserver | ≤ 13.0.2 | Yes |
Application | rockwellautomation | thinmanager_thinserver | 13.1.0 | Yes |