CVE-2024-7987
26.08.2024, 15:15
A remote code execution vulnerability exists in the Rockwell AutomationThinManager ThinServer that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer service by creating a junction and use it to upload arbitrary files.Enginsight
| Vendor | Product | Version |
|---|---|---|
| rockwellautomation | thinmanager_thinserver | 11.1.0 ≤ 𝑥 < 11.1.8 |
| rockwellautomation | thinmanager_thinserver | 11.2.0 ≤ 𝑥 < 11.2.9 |
| rockwellautomation | thinmanager_thinserver | 12.0.0 ≤ 𝑥 < 12.0.7 |
| rockwellautomation | thinmanager_thinserver | 12.1.0 ≤ 𝑥 < 12.1.8 |
| rockwellautomation | thinmanager_thinserver | 13.0.0 ≤ 𝑥 < 13.0.5 |
| rockwellautomation | thinmanager_thinserver | 13.1.0 ≤ 𝑥 < 13.1.3 |
| rockwellautomation | thinmanager_thinserver | 13.2.0 ≤ 𝑥 < 13.2.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration