CVE Vulnerabilities

CVE-2024-5990

Published: Jun 25, 2024 | Modified: Sep 16, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServerâ„¢ and cause a denial-of-service condition on the affected device.

Affected Software

Name Vendor Start Version End Version
Thinmanager Rockwellautomation 11.1.0 (including) 11.1.8 (excluding)
Thinmanager Rockwellautomation 11.2.0 (including) 11.2.9 (excluding)
Thinmanager Rockwellautomation 12.0.0 (including) 12.0.7 (excluding)
Thinmanager Rockwellautomation 12.1.0 (including) 12.1.8 (excluding)
Thinmanager Rockwellautomation 13.0.0 (including) 13.0.4 (excluding)
Thinmanager Rockwellautomation 13.1.0 (including) 13.1.2 (excluding)
Thinserver Rockwellautomation 11.1.0 (including) 11.1.8 (excluding)
Thinserver Rockwellautomation 11.2.0 (including) 11.2.9 (excluding)
Thinserver Rockwellautomation 12.0.0 (including) 12.0.7 (excluding)
Thinserver Rockwellautomation 12.1.0 (including) 12.1.8 (excluding)
Thinserver Rockwellautomation 13.0.0 (including) 13.0.4 (excluding)
Thinserver Rockwellautomation 13.1.0 (including) 13.1.2 (excluding)

References