PT-2024-4322 · Rockwell Automation · Thinmanager

CVE-2024-5989

·

Published

2024-06-25

·

Updated

2024-09-16

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Rockwell Automation ThinManager ThinServer (affected versions not specified)
Description The issue is related to improper input validation in the ThinServer component of Rockwell Automation ThinManager, allowing an unauthenticated threat actor to send a malicious message and invoke SQL injection into the program. This can cause a remote code execution condition. The exploitation involves sending a specially crafted SQL query.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04810
CVE-2024-5989

Affected Products

Thinmanager