9.8
CVE-2024-7988
- EPSS 15.07%
- Veröffentlicht 26.08.2024 15:15:09
- Zuletzt bearbeitet 21.10.2025 18:58:17
- Quelle PSIRT@rockwellautomation.com
- CVE-Watchlists
- Unerledigt
A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rockwellautomation ≫ Thinmanager Thinserver Version >= 11.1.0 < 11.1.8
Rockwellautomation ≫ Thinmanager Thinserver Version >= 11.2.0 < 11.2.9
Rockwellautomation ≫ Thinmanager Thinserver Version >= 12.0.0 < 12.0.7
Rockwellautomation ≫ Thinmanager Thinserver Version >= 12.1.0 < 12.1.8
Rockwellautomation ≫ Thinmanager Thinserver Version >= 13.0.0 < 13.0.5
Rockwellautomation ≫ Thinmanager Thinserver Version >= 13.1.0 < 13.1.3
Rockwellautomation ≫ Thinmanager Thinserver Version >= 13.2.0 < 13.2.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 15.07% | 0.943 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| PSIRT@rockwellautomation.com | 9.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.