📦 Thinmanager

by Rockwellautomation

🔍 What is Thinmanager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-10386

CRITICAL CVSS 9.8 Oct 25, 2024

CVE-2024-10386 is a critical authentication vulnerability in Rockwell Automation products that allows unauthenticated attackers with network access to send crafted messages to manipulate databases. Th...

CVE-2024-5988

CRITICAL CVSS 9.8 Jun 25, 2024

CVE-2024-5988 is a critical remote code execution vulnerability in Rockwell Automation ThinManager ThinServer. Unauthenticated attackers can send malicious messages to execute arbitrary code on affect...

CVE-2023-27855

CRITICAL CVSS 9.8 Mar 22, 2023

CVE-2023-27855 is a critical path traversal vulnerability in Rockwell Automation's ThinManager ThinServer that allows unauthenticated remote attackers to upload arbitrary files to any directory where ...

CVE-2025-9065

HIGH CVSS 8.8 Sep 9, 2025

This CVE describes a server-side request forgery (SSRF) vulnerability in Rockwell Automation ThinManager software where authenticated attackers can force the server to make requests to external SMB sh...

CVE-2025-3617

HIGH CVSS 7.8 Apr 15, 2025

A privilege escalation vulnerability in Rockwell Automation ThinManager allows attackers to inherit elevated permissions when temporary files are deleted during startup. This affects organizations usi...

CVE-2024-7986

HIGH CVSS 7.5 Aug 23, 2024

This vulnerability in Rockwell Automation ThinManager ThinServer allows attackers to read arbitrary files by exploiting directory junction points. It affects organizations using vulnerable versions of...

CVE-2024-5990

HIGH CVSS 7.5 Jun 25, 2024

CVE-2024-5990 is an improper input validation vulnerability in Rockwell Automation ThinServer™ that allows unauthenticated attackers to send malicious messages to monitor threads, causing denial-of-...

CVE-2023-2913

HIGH CVSS 7.5 Jul 18, 2023

A path traversal vulnerability in Rockwell Automation ThinManager ThinServer allows remote attackers to read arbitrary files on the server's file system when the API feature is enabled. This affects s...

CVE-2023-27857

HIGH CVSS 7.5 Mar 22, 2023

This vulnerability in Rockwell Automation's ThinManager ThinServer allows unauthenticated remote attackers to trigger a heap-based buffer over-read by sending specially crafted messages. Exploitation ...

CVE-2024-45826

MEDIUM CVSS 6.8 Sep 12, 2024

CVE-2024-45826 is a path traversal and remote code execution vulnerability in ThinManager® that allows attackers to install executable files via crafted POST requests. This affects organizations usin...