Vulnerabilities > Rockwellautomation > Thinmanager > 12.1.5

DATE CVE VULNERABILITY TITLE RISK
2024-10-25 CVE-2024-10386 Unspecified vulnerability in Rockwellautomation Thinmanager
CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product.
network
low complexity
rockwellautomation
critical
9.8
2024-10-25 CVE-2024-10387 Unspecified vulnerability in Rockwellautomation Thinmanager
CVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product.
network
low complexity
rockwellautomation
7.5
2024-08-23 CVE-2024-7986 Unspecified vulnerability in Rockwellautomation Thinmanager
A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information.
network
low complexity
rockwellautomation
7.5
2024-06-25 CVE-2024-5988 Unspecified vulnerability in Rockwellautomation Thinmanager and Thinserver
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.
network
low complexity
rockwellautomation
critical
9.8
2024-06-25 CVE-2024-5989 Unspecified vulnerability in Rockwellautomation Thinmanager and Thinserver
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.
network
low complexity
rockwellautomation
critical
9.8
2024-06-25 CVE-2024-5990 Unspecified vulnerability in Rockwellautomation Thinmanager and Thinserver
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServer™ and cause a denial-of-service condition on the affected device.
network
low complexity
rockwellautomation
7.5
2023-05-11 CVE-2023-2443 Inadequate Encryption Strength vulnerability in Rockwellautomation Thinmanager
Rockwell Automation ThinManager product allows the use of medium strength ciphers.
network
low complexity
rockwellautomation CWE-326
7.5
2023-03-22 CVE-2023-27855 Path Traversal vulnerability in Rockwellautomation Thinmanager
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer.
network
low complexity
rockwellautomation CWE-22
critical
9.8
2023-03-22 CVE-2023-27856 Path Traversal vulnerability in Rockwellautomation Thinmanager
In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer.
network
low complexity
rockwellautomation CWE-22
7.5
2022-09-23 CVE-2022-38742 Out-of-bounds Write vulnerability in Rockwellautomation Thinmanager
Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow.
network
low complexity
rockwellautomation CWE-787
critical
9.8