CVE-2024-7986
23.08.2024, 12:15
A vulnerability exists in the Rockwell AutomationThinManager ThinServerthat allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer service to read arbitrary files by creating a junction that points to the target directory.Enginsight
Vendor | Product | Version |
---|---|---|
rockwellautomation | thinmanager | 11.1.0 ≤ 𝑥 < 11.1.8 |
rockwellautomation | thinmanager | 11.2.0 ≤ 𝑥 < 11.2.9 |
rockwellautomation | thinmanager | 12.0.0 ≤ 𝑥 < 12.0.7 |
rockwellautomation | thinmanager | 12.1.0 ≤ 𝑥 < 12.1.8 |
rockwellautomation | thinmanager | 13.0.0 ≤ 𝑥 < 13.0.5 |
rockwellautomation | thinmanager | 13.1.0 ≤ 𝑥 < 13.1.3 |
rockwellautomation | thinmanager | 13.2.0 ≤ 𝑥 < 13.2.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration