← Back

CVE-2024-7986

nvd nist
Published: Aug 23, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.8
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: PSIRT@rockwellautomation.com (Secondary)

Description

A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that points to the target directory.

Affected (7)

Thinmanager
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
From 11.1.0 to 11.1.8
From 11.2.0 to 11.2.9
From 12.0.0 to 12.0.7
From 12.1.0 to 12.1.8
From 13.0.0 to 13.0.5
From 13.1.0 to 13.1.3
From 13.2.0 to 13.2.2

References (1)

Timeline

No history available yet.