CVE-2024-7986: Rockwell Automation ThinManager® ThinServer™ Information Disclosure
A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that points to the target directory.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7986?
CVE-2024-7986 is considered a high severity vulnerability due to the potential for sensitive information disclosure.
How do I fix CVE-2024-7986?
To fix CVE-2024-7986, it is recommended to apply the latest security patches provided by Rockwell Automation for the ThinManager ThinServer.
What is the impact of CVE-2024-7986?
The impact of CVE-2024-7986 allows threat actors to read arbitrary files, which can lead to unauthorized access to sensitive data.
Who is affected by CVE-2024-7986?
Organizations using Rockwell Automation ThinManager ThinServer are affected by CVE-2024-7986.
Is there a workaround for CVE-2024-7986?
Currently, no specific workaround is provided for CVE-2024-7986, so it is essential to apply the recommended updates.