CVE-2024-5989: Rockwell Automation ThinManager® ThinServer™ Improper Input Validation Vulnerability
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 11.1.8 - Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 11.2.9 - Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 12.0.7 - Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 12.1.8 - Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 13.0.5 - Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 13.0.4 - Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 13.1.3 - Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 13.1.2 - Upgrade
Upgrade
Rockwell Automation ThinManager ThinServerto a version that resolves this vulnerability.Fixed in 13.2.2 - Compensating control
Limit remote access for TCP Port 2031 to known thin clients and ThinManager ThinServer servers.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5989?
CVE-2024-5989 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-5989?
To fix CVE-2024-5989, update Rockwell Automation ThinManager and ThinServer to the latest patched versions as provided by the vendor.
What types of systems are affected by CVE-2024-5989?
CVE-2024-5989 affects specific versions of Rockwell Automation ThinManager and ThinServer software, specifically versions between 11.1.0 to 13.2.2.
Who can exploit CVE-2024-5989?
CVE-2024-5989 can be exploited by unauthenticated threat actors who can send malicious input to the affected systems.
What kind of attack does CVE-2024-5989 enable?
CVE-2024-5989 enables SQL injection attacks that could lead to remote code execution on the vulnerable systems.