PT-2024-4322 · Rockwell Automation · Thinmanager

Published

2024-06-25

·

Updated

2024-09-16

·

CVE-2024-5989

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Rockwell Automation ThinManager ThinServer (affected versions not specified)
Description The issue is related to improper input validation in the ThinServer component of Rockwell Automation ThinManager, allowing an unauthenticated threat actor to send a malicious message and invoke SQL injection into the program. This can cause a remote code execution condition. The exploitation involves sending a specially crafted SQL query.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-04810
CVE-2024-5989

Affected Products

Thinmanager