Vulnerabilities > Rockwellautomation > Thinmanager > 11.1.5

DATE CVE VULNERABILITY TITLE RISK
2024-08-23 CVE-2024-7986 Unspecified vulnerability in Rockwellautomation Thinmanager
A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information.
network
low complexity
rockwellautomation
7.5
2024-06-25 CVE-2024-5988 Unspecified vulnerability in Rockwellautomation Thinmanager and Thinserver
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.
network
low complexity
rockwellautomation
critical
9.8
2024-06-25 CVE-2024-5989 Unspecified vulnerability in Rockwellautomation Thinmanager and Thinserver
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.
network
low complexity
rockwellautomation
critical
9.8
2024-06-25 CVE-2024-5990 Unspecified vulnerability in Rockwellautomation Thinmanager and Thinserver
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServer™ and cause a denial-of-service condition on the affected device.
network
low complexity
rockwellautomation
7.5
2023-05-11 CVE-2023-2443 Inadequate Encryption Strength vulnerability in Rockwellautomation Thinmanager
Rockwell Automation ThinManager product allows the use of medium strength ciphers.
network
low complexity
rockwellautomation CWE-326
7.5
2022-09-23 CVE-2022-38742 Out-of-bounds Write vulnerability in Rockwellautomation Thinmanager
Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow.
network
low complexity
rockwellautomation CWE-787
critical
9.8