Known vulnerabilities in ThinManager

Software: ThinManager
Software CPE: cpe:2.3:a:rockwell_automation:thinmanager:*:*:*:*:*:*:*:*
Total vulnerabilities: 21
Public exploits: 4
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ThinManager ThinManager is affected by 21 known vulnerabilities: 8 high, 9 medium, 4 low Critical High Medium Low

Vulnerabilities (21)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU115148 - Server-Side Request Forgery (SSRF)
CVE-2025-9065
CWE-918 Medium
No
No
14.1 10.09.2025 SB2025091043
#VU108167 - Incorrect Default Permissions
CVE-2025-3617
CWE-276 Low
No
No
14.0.2 02.05.2025 SB2025050259
#VU108166 - Memory corruption
CVE-2025-3618
CWE-119 High
No
No
11.2.11, 12.0.9, 13.1.5, 13.2.4, 14.0.2 02.05.2025 SB2025050259
#VU99574 - Out-of-bounds read
CVE-2024-10387
CWE-125 Medium
No
No
11.2.10, 12.0.8, 12.1.9, 13.0.6, 13.1.4, 14.0.1 01.11.2024 SB2024110103
#VU99573 - Missing Authentication for Critical Function
CVE-2024-10386
CWE-306 High
No
No
11.2.10, 12.0.8, 12.1.9, 13.0.6, 13.1.4, 14.0.1 01.11.2024 SB2024110103
#VU97308 - Externally Controlled Reference to a Resource in Another Sphere
CVE-2024-45826
CWE-610 Low
No
No
13.1.3, 13.2.2 16.09.2024 SB2024091616
#VU96480 - Improper Privilege Management
CVE-2024-7986
CWE-269 Low
No
No
11.1.8, 11.2.9, 12.0.7, 12.1.8, 13.0.5, 13.1.3, 13.2.2 23.08.2024 SB2024082329
#VU96478 - Incorrect Permission Assignment for Critical Resource
CVE-2024-7987
CWE-732 Low
No
No
11.1.8, 11.2.9, 12.0.7, 12.1.8, 13.0.5, 13.1.3, 13.2.2 23.08.2024 SB2024082329
#VU96477 - Unrestricted Upload of File with Dangerous Type
CVE-2024-7988
CWE-434 High
No
No
11.1.8, 11.2.9, 12.0.7, 12.1.8, 13.0.5, 13.1.3, 13.2.2 23.08.2024 SB2024082329
#VU94180 - Improper input validation
CVE-2024-5990
CWE-20 Medium
No
No
11.1.8, 11.2.9, 12.0.7, 12.1.8, 13.0.5, 13.1.3, 13.2.2 12.07.2024 SB2024071205
#VU94179 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-5989
CWE-89 High
No
No
11.1.8, 11.2.9, 12.0.7, 12.1.8, 13.0.5, 13.1.3, 13.2.2 12.07.2024 SB2024071205
#VU94178 - Improper input validation
CVE-2024-5988
CWE-20 High
No
No
11.1.8, 11.2.9, 12.0.7, 12.1.8, 13.0.5, 13.1.3, 13.2.2 12.07.2024 SB2024071205
#VU80035 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-2917
CWE-22 High
Available
Exploited
11.0.7, 11.1.7, 11.2.8, 12.0.6, 12.1.7, 13.0.3, 13.1.1 28.08.2023 SB2023082822
#VU80032 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-2915
CWE-22 Medium
Available
Exploited
11.0.7, 11.1.7, 11.2.8, 12.0.6, 12.1.7, 13.0.3, 13.1.1 28.08.2023 SB2023082822
#VU80031 - Improper input validation
CVE-2023-2914
CWE-20 Medium
No
No
11.0.7, 11.1.7, 11.2.8, 12.0.6, 12.1.7, 13.0.3, 13.1.1 28.08.2023 SB2023082822
#VU78686 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-2913
CWE-22 Medium
No
No
13.0.3, 13.1.1 26.07.2023 SB2023072638
#VU77800 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-27855
CWE-22 Medium
Available
Exploited
- 29.06.2023 SB2023032414
#VU77799 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-27856
CWE-22 High
Available
Exploited
- 29.06.2023 SB2023032414
#VU76071 - Inadequate Encryption Strength
CVE-2023-2443
CWE-326 Medium
No
No
13.0.2 12.05.2023 SB2023051215
#VU74008 - Heap-based Buffer Overflow
CVE-2023-27857
CWE-122 Medium
No
No
- 24.03.2023 SB2023032414


Showing elements 1 - 20 out of 21