Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-9065


A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing the ThinServer® service account NTLM hash.


Published

2025-09-09T13:15:32.493

Last Modified

2025-10-20T19:17:27.270

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-610
  • Type: Primary
    CWE-918

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rockwellautomation thinmanager ≤ 14.0.0 Yes

References