CVE-2024-10387: Rockwell Automation FactoryTalk ThinManager Denial-of-Service Vulnerability
Published Oct 25, 2024
·Updated
CVE-2024-10387 IMPACT
A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in Denial-of-Service.
Affected Software
7 affected components
rockwellautomation Thinmanager>=11.2.0<11.2.10
rockwellautomation Thinmanager>=12.0.0<12.0.8
rockwellautomation Thinmanager>=12.1.0<12.1.9
rockwellautomation Thinmanager>=13.0.0<13.0.6
rockwellautomation Thinmanager>=13.1.0<=13.1.4
rockwellautomation Thinmanager>=13.2.0<=13.2.3
rockwellautomation Thinmanager=14.0.0
Remediation
Information
If able,
navigate to the ThinManager® download site https://thinmanager.com/downloads/ and upgrade to a corrected version of ThinManager®
11.2.10
12.0.8
12.1.9
13.0.6
13.1.4
13.2.3
14.0.1
Event History
Oct 25, 2024
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10387?
CVE-2024-10387 has been classified as a Denial-of-Service vulnerability.
2
How do I fix CVE-2024-10387?
To mitigate CVE-2024-10387, update Rockwell Automation ThinManager to the latest patched version.
3
What products are affected by CVE-2024-10387?
CVE-2024-10387 affects multiple versions of Rockwell Automation ThinManager, specifically versions between 11.2.0 and 14.0.0.
4
Can CVE-2024-10387 be exploited remotely?
Yes, CVE-2024-10387 can be exploited by a threat actor with network access.
5
What impact does CVE-2024-10387 have on affected systems?
CVE-2024-10387 can lead to a Denial-of-Service condition on the affected devices.