← Back

CVE-2024-5989

nvd nist
Published: Jun 25, 2024Modified: Jun 17, 2026

JSON object

Loading...
9.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: PSIRT@rockwellautomation.com (Secondary)

Description

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.

Affected (14)

Thinmanager
Thinserver
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
From 11.1.0 to 11.1.8
From 11.2.0 to 11.2.9
From 12.0.0 to 12.0.7
From 12.1.0 to 12.1.8
From 13.0.0 to 13.0.5
From 13.1.0 to 13.1.3
From 13.2.0 to 13.2.2
From 11.1.0 to 11.1.8
From 11.2.0 to 11.2.9
From 12.0.0 to 12.0.7
From 12.1.0 to 12.1.8
From 13.0.0 to 13.0.5
From 13.1.0 to 13.1.3
From 13.2.0 to 13.2.2

Timeline

No history available yet.