Known vulnerabilities in ThinServer

Software: ThinServer
Software CPE: cpe:2.3:a:rockwell_automation:thinserver:*:*:*:*:*:*:*:*
Total vulnerabilities: 11
Public exploits: 2
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ThinServer ThinServer is affected by 11 known vulnerabilities: 5 high, 4 medium, 2 low Critical High Medium Low

Vulnerabilities (11)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU96480 - Improper Privilege Management
CVE-2024-7986
CWE-269 Low
No
No
11.1.8, 11.2.9, 12.0.7, 12.1.8, 13.0.5, 13.1.3, 13.2.2 23.08.2024 SB2024082329
#VU96478 - Incorrect Permission Assignment for Critical Resource
CVE-2024-7987
CWE-732 Low
No
No
11.1.8, 11.2.9, 12.0.7, 12.1.8, 13.0.5, 13.1.3, 13.2.2 23.08.2024 SB2024082329
#VU96477 - Unrestricted Upload of File with Dangerous Type
CVE-2024-7988
CWE-434 High
No
No
11.1.8, 11.2.9, 12.0.7, 12.1.8, 13.0.5, 13.1.3, 13.2.2 23.08.2024 SB2024082329
#VU94180 - Improper input validation
CVE-2024-5990
CWE-20 Medium
No
No
- 12.07.2024 SB2024071205
#VU94179 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-5989
CWE-89 High
No
No
- 12.07.2024 SB2024071205
#VU94178 - Improper input validation
CVE-2024-5988
CWE-20 High
No
No
- 12.07.2024 SB2024071205
#VU80035 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-2917
CWE-22 High
Available
Exploited
11.0.7, 11.1.7, 11.2.8, 12.0.6, 12.1.7, 13.0.3, 13.1.1 28.08.2023 SB2023082822
#VU80032 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-2915
CWE-22 Medium
Available
Exploited
11.0.7, 11.1.7, 11.2.8, 12.0.6, 12.1.7, 13.0.3, 13.1.1 28.08.2023 SB2023082822
#VU80031 - Improper input validation
CVE-2023-2914
CWE-20 Medium
No
No
11.0.7, 11.1.7, 11.2.8, 12.0.6, 12.1.7, 13.0.3, 13.1.1 28.08.2023 SB2023082822
#VU78686 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-2913
CWE-22 Medium
No
No
13.0.3, 13.1.1 26.07.2023 SB2023072638
#VU67765 - Heap-based Buffer Overflow
CVE-2022-38742
CWE-122 High
No
No
11.00.05, 11.01.05, 11.02.06, 12.00.03, 12.01.04, 13.00.01 30.09.2022 SB2022093002