CVE-2024-10386: Rockwell Automation FactoryTalk ThinManager Authentication Vulnerability
CVE-2024-10386 IMPACT
An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in database manipulation.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10386?
CVE-2024-10386 has been classified with a critical severity due to its potential for authentication bypass and database manipulation.
How do I fix CVE-2024-10386?
To fix CVE-2024-10386, update the Rockwell Automation ThinManager to the latest version that addresses this vulnerability.
What products are affected by CVE-2024-10386?
The affected products include various versions of Rockwell Automation ThinManager, specifically versions 11.2.0 to 11.2.10, 12.0.0 to 12.0.8, 12.1.0 to 12.1.9, 13.0.0 to 13.0.6, 13.1.0 to 13.1.4, 13.2.0 to 13.2.3, and 14.0.0.
Can CVE-2024-10386 be exploited remotely?
Yes, CVE-2024-10386 can be exploited remotely by a threat actor with network access to the affected devices.
What impact does CVE-2024-10386 have on my system?
CVE-2024-10386 could potentially allow a threat actor to manipulate the database by sending crafted messages to the device.