CVE-2024-5988: Rockwell Automation ThinManager® ThinServer™ Improper Input Validation Vulnerability
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 11.1.8 - Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 11.2.9 - Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 12.0.7 - Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 12.1.8 - Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 13.0.5 - Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 13.1.3 - Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 13.2.2 - Compensating control
Limit remote access for TCP Port 2031 to known thin clients and ThinManager ThinServer (per mitigation list in the provided advisory).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5988?
CVE-2024-5988 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-5988?
To fix CVE-2024-5988, update the Rockwell Automation ThinManager and ThinServer to the latest versions provided by the vendor.
What are the affected versions for CVE-2024-5988?
CVE-2024-5988 affects Rockwell Automation ThinManager and ThinServer versions from 11.1.0 to 13.2.2.
What type of vulnerability is CVE-2024-5988?
CVE-2024-5988 is classified as a remote code execution vulnerability due to improper input validation.
Can CVE-2024-5988 be exploited by an authenticated user?
No, CVE-2024-5988 can be exploited by an unauthenticated threat actor.