Skip to main content

Vendor/product archive

rockwellautomation / thinmanager CVEs

Beta · best-effort

16 CVEs tagged to rockwellautomation / thinmanager4 Critical, 11 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2025-9065

Published Sep 9, 2025

A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit thi…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3618

Published Apr 15, 2025

A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify the outcome of memory allocation while processing Type 18…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3617

Published Apr 15, 2025

A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary folder causing the Access Contr…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10387

Published Oct 25, 2024

CVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted message…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10386

Published Oct 25, 2024

CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45826

Published Sep 12, 2024

CVE-2024-45826 IMPACT Due to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® processes a crafted POST request. If…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7986

Published Aug 23, 2024

A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerabili…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2913

Published Jul 18, 2023

An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This feature is disabled by default. When…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2443

Published May 11, 2023

Rockwell Automation ThinManager product allows the use of medium strength ciphers.  If the client requests an insecure cipher, a malicious actor could potentially decrypt traffic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27857

Published Mar 22, 2023

In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's T…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27856

Published Mar 22, 2023

In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27855

Published Mar 22, 2023

In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially explo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-38742

Published Sep 23, 2022

Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifically crafted TFTP or HTTPS requ…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1