First published: Fri Sep 23 2022(Updated: )
Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifically crafted TFTP or HTTPS request, causing a heap-based buffer overflow that crashes the ThinServer process. If successfully exploited, this could expose the server to arbitrary remote code execution.
Credit: PSIRT@rockwellautomation.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwellautomation Thinmanager | >=11.0.0<=13.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of Rockwell Automation ThinManager ThinServer is CVE-2022-38742.
CVE-2022-38742 has a severity value of 9.8 (Critical).
Versions 11.0.0 to 13.0.0 of Rockwell Automation ThinManager ThinServer are affected by this vulnerability.
The vulnerability in Rockwell Automation ThinManager ThinServer manifests as a heap-based buffer overflow when processing TFTP or HTTPS requests.
For information on available fixes or patches for CVE-2022-38742, please refer to the Rockwell Automation customer support website.