Vulnerability Description
A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that points to the target directory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Thinmanager | >= 11.1.0, < 11.1.8 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-7986?
CVE-2024-7986 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the Thi...
How severe is CVE-2024-7986?
CVE-2024-7986 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-7986?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Thinmanager.