A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that points to the target directory.
2024-08-23T12:15:03.920
2025-03-03T19:11:33.343
Analyzed
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | rockwellautomation | thinmanager | < 11.1.8 | Yes |
Application | rockwellautomation | thinmanager | < 11.2.9 | Yes |
Application | rockwellautomation | thinmanager | < 12.0.7 | Yes |
Application | rockwellautomation | thinmanager | < 12.1.8 | Yes |
Application | rockwellautomation | thinmanager | < 13.0.5 | Yes |
Application | rockwellautomation | thinmanager | < 13.1.3 | Yes |
Application | rockwellautomation | thinmanager | < 13.2.2 | Yes |