CVE-2024-7988

Severity CVSS v4.0:
CRITICAL
Type:
CWE-20 Input Validation
Publication date:
26/08/2024
Last modified:
21/10/2025

Description

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:* 11.1.0 (including) 11.1.8 (excluding)
cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:* 11.2.0 (including) 11.2.9 (excluding)
cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:* 12.0.0 (including) 12.0.7 (excluding)
cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:* 12.1.0 (including) 12.1.8 (excluding)
cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:* 13.0.0 (including) 13.0.5 (excluding)
cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:* 13.1.0 (including) 13.1.3 (excluding)
cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:* 13.2.0 (including) 13.2.2 (excluding)