← Back

CVE-2024-7987

nvd nist
Published: Aug 26, 2024Modified: Oct 21, 2025

JSON object

Loading...
8.5
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: PSIRT@rockwellautomation.com (Secondary)

Description

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to upload arbitrary files.

Affected (7)

Thinmanager Thinserver
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
From 11.1.0 to 11.1.8
From 11.2.0 to 11.2.9
From 12.0.0 to 12.0.7
From 12.1.0 to 12.1.8
From 13.0.0 to 13.0.5
From 13.1.0 to 13.1.3
From 13.2.0 to 13.2.2

References (1)

Timeline

No history available yet.