Known vulnerabilities in ThinServer
Vendor:
Rockwell Automation
Software:
ThinServer
Software CPE:
cpe:2.3:a:rockwell_automation:thinserver:*:*:*:*:*:*:*:*
Website:
https://www.rockwellautomation.com/
Total vulnerabilities:
11
Public exploits:
2
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
13.2.2
13.2.1
13.1.3
13.1.2
13.0.5
13.0.4
12.1.8
12.0.7
11.2.9
11.1.8
13.2.0
11.2.8
12.0.6
12.0.5
12.0.4
12.0.3
12.1.7
12.1.6
12.1.5
12.1.4
11.2.7
11.2.6
11.1.7
11.1.6
11.1.5
11.0.7
11.0.6
13.1.0
13.0.2
13.0.1
13.1.1
13.0.3
11.00.05
11.01.05
11.02.06
12.00.03
12.01.04
13.00.01
13.0.0
12.1.3
12.1.2
12.1.1
12.1.0
12.0.2
12.0.1
12.0.0
11.2.5
11.2.4
11.2.3
11.2.2
11.2.1
11.2.0
11.1.4
11.1.3
11.1.2
11.1.1
11.1.0
11.0.5
11.0.4
11.0.3
11.0.2
11.0.1
11.0.0
Vulnerabilities (11)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU96480 - Improper Privilege Management CVE-2024-7986 |
CWE-269 | Low | 11.1.8, 11.2.9, 12.0.7, 12.1.8, 13.0.5, 13.1.3, 13.2.2 | 23.08.2024 |
SB2024082329 |
||
| #VU96478 - Incorrect Permission Assignment for Critical Resource CVE-2024-7987 |
CWE-732 | Low | 11.1.8, 11.2.9, 12.0.7, 12.1.8, 13.0.5, 13.1.3, 13.2.2 | 23.08.2024 |
SB2024082329 |
||
| #VU96477 - Unrestricted Upload of File with Dangerous Type CVE-2024-7988 |
CWE-434 | High | 11.1.8, 11.2.9, 12.0.7, 12.1.8, 13.0.5, 13.1.3, 13.2.2 | 23.08.2024 |
SB2024082329 |
||
| #VU94180 - Improper input validation CVE-2024-5990 |
CWE-20 | Medium | - | 12.07.2024 |
SB2024071205 |
||
| #VU94179 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-5989 |
CWE-89 | High | - | 12.07.2024 |
SB2024071205 |
||
| #VU94178 - Improper input validation CVE-2024-5988 |
CWE-20 | High | - | 12.07.2024 |
SB2024071205 |
||
| #VU80035 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2023-2917 |
CWE-22 | High | 11.0.7, 11.1.7, 11.2.8, 12.0.6, 12.1.7, 13.0.3, 13.1.1 | 28.08.2023 |
SB2023082822 |
||
| #VU80032 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2023-2915 |
CWE-22 | Medium | 11.0.7, 11.1.7, 11.2.8, 12.0.6, 12.1.7, 13.0.3, 13.1.1 | 28.08.2023 |
SB2023082822 |
||
| #VU80031 - Improper input validation CVE-2023-2914 |
CWE-20 | Medium | 11.0.7, 11.1.7, 11.2.8, 12.0.6, 12.1.7, 13.0.3, 13.1.1 | 28.08.2023 |
SB2023082822 |
||
| #VU78686 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2023-2913 |
CWE-22 | Medium | 13.0.3, 13.1.1 | 26.07.2023 |
SB2023072638 |
||
| #VU67765 - Heap-based Buffer Overflow CVE-2022-38742 |
CWE-122 | High | 11.00.05, 11.01.05, 11.02.06, 12.00.03, 12.01.04, 13.00.01 | 30.09.2022 |
SB2022093002 |