A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that points to the target directory.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Thinmanager | Rockwellautomation | 11.1.0 (including) | 11.1.8 (excluding) |
| Thinmanager | Rockwellautomation | 11.2.0 (including) | 11.2.9 (excluding) |
| Thinmanager | Rockwellautomation | 12.0.0 (including) | 12.0.7 (excluding) |
| Thinmanager | Rockwellautomation | 12.1.0 (including) | 12.1.8 (excluding) |
| Thinmanager | Rockwellautomation | 13.0.0 (including) | 13.0.5 (excluding) |
| Thinmanager | Rockwellautomation | 13.1.0 (including) | 13.1.3 (excluding) |
| Thinmanager | Rockwellautomation | 13.2.0 (including) | 13.2.2 (excluding) |