Home/Product/rockwellautomation thinmanager
Product

rockwellautomation thinmanager

16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-9065
>= 13.0.0 and <= 14.0.0
A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input san
8.8HIGH
CVE-2025-3618
< 11.2.11
A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify the outco
5.5MEDIUM
CVE-2025-3617
>= 14.0.0 and < 14.0.2
A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted
7.8HIGH
CVE-2024-10387
>= 11.2.0 and < 11.2.10
CVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow a threat
7.5HIGH
CVE-2024-10386
>= 11.2.0 and < 11.2.10
CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat ac
9.8CRITICAL
CVE-2024-45826
>= 13.1.0 and < 13.1.3
CVE-2024-45826 IMPACT Due to improper input validation, a path traversal and remote code execution vulnerability exists when the T
6.8MEDIUM
CVE-2024-7986
>= 11.1.0 and < 11.1.8
A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive info
7.5HIGH
CVE-2024-5990
>= 11.1.0 and < 11.1.8
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockw
7.5HIGH
CVE-2024-5989
>= 11.1.0 and < 11.1.8
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the
9.8CRITICAL
CVE-2024-5988
>= 11.1.0 and < 11.1.8
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote exec
9.8CRITICAL
CVE-2023-2913
>= 13.0.0 and <= 13.0.2
An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Se
7.5HIGH
CVE-2023-2443
<= 13.0
Rockwell Automation ThinManager product allows the use of medium strength ciphers. If the client requests an insecure cipher, a
7.5HIGH
CVE-2023-27857
>= 11.0.0 and < 11.0.5
In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in
7.5HIGH
CVE-2023-27856
>= 6.0.0 and <= 10.0.2
In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer.
7.5HIGH
CVE-2023-27855
>= 6.0.0 and <= 10.0.2
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauth
9.8CRITICAL
CVE-2022-38742
>= 11.0.0 and <= 13.0.0
Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker cou
8.1HIGH
threatengine.sh