CVE-2024-7988

EUVD-2024-48819
A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
Affected Products (NVD)
VendorProductVersion
rockwellautomationthinmanager_thinserver
11.1.0 ≤
𝑥
< 11.1.8
rockwellautomationthinmanager_thinserver
11.2.0 ≤
𝑥
< 11.2.9
rockwellautomationthinmanager_thinserver
12.0.0 ≤
𝑥
< 12.0.7
rockwellautomationthinmanager_thinserver
12.1.0 ≤
𝑥
< 12.1.8
rockwellautomationthinmanager_thinserver
13.0.0 ≤
𝑥
< 13.0.5
rockwellautomationthinmanager_thinserver
13.1.0 ≤
𝑥
< 13.1.3
rockwellautomationthinmanager_thinserver
13.2.0 ≤
𝑥
< 13.2.2
𝑥
= Vulnerable software versions