Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-5989


Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.


Published

2024-06-25T16:15:25.363

Last Modified

2024-11-21T09:48:42.330

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rockwellautomation thinmanager < 11.1.8 Yes
Application rockwellautomation thinmanager < 11.2.9 Yes
Application rockwellautomation thinmanager < 12.0.7 Yes
Application rockwellautomation thinmanager < 12.1.8 Yes
Application rockwellautomation thinmanager < 13.0.5 Yes
Application rockwellautomation thinmanager < 13.1.3 Yes
Application rockwellautomation thinmanager < 13.2.2 Yes
Application rockwellautomation thinserver < 11.1.8 Yes
Application rockwellautomation thinserver < 11.2.9 Yes
Application rockwellautomation thinserver < 12.0.7 Yes
Application rockwellautomation thinserver < 12.1.8 Yes
Application rockwellautomation thinserver < 13.0.5 Yes
Application rockwellautomation thinserver < 13.1.3 Yes
Application rockwellautomation thinserver < 13.2.2 Yes

References