CVE-2024-7987

HIGH

Rockwell Automation ThinManager ThinServer - RCE

Title source: llm
STIX 2.1

Description

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to upload arbitrary files.

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 32.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
rockwellautomation/thinmanager_thinserver 11.1.0 - 11.1.8
Published Aug 26, 2024
Tracked Since Feb 18, 2026