CVE Vulnerabilities

CVE-2024-5988

Published: Jun 25, 2024 | Modified: Sep 16, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.

Affected Software

Name Vendor Start Version End Version
Thinmanager Rockwellautomation 11.1.0 (including) 11.1.8 (excluding)
Thinmanager Rockwellautomation 11.2.0 (including) 11.2.9 (excluding)
Thinmanager Rockwellautomation 12.0.0 (including) 12.0.7 (excluding)
Thinmanager Rockwellautomation 12.1.0 (including) 12.1.8 (excluding)
Thinmanager Rockwellautomation 13.0.0 (including) 13.0.5 (excluding)
Thinmanager Rockwellautomation 13.1.0 (including) 13.1.3 (excluding)
Thinmanager Rockwellautomation 13.2.0 (including) 13.2.2 (excluding)
Thinserver Rockwellautomation 11.1.0 (including) 11.1.8 (excluding)
Thinserver Rockwellautomation 11.2.0 (including) 11.2.9 (excluding)
Thinserver Rockwellautomation 12.0.0 (including) 12.0.7 (excluding)
Thinserver Rockwellautomation 12.1.0 (including) 12.1.8 (excluding)
Thinserver Rockwellautomation 13.0.0 (including) 13.0.5 (excluding)
Thinserver Rockwellautomation 13.1.0 (including) 13.1.3 (excluding)
Thinserver Rockwellautomation 13.2.0 (including) 13.2.2 (excluding)

References