CVE-2024-7987: Rockwell Automation ThinManager® ThinServer™ Information Disclosure and Remote Code Execution Vulnerabilities
A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to upload arbitrary files.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7987?
CVE-2024-7987 has a high severity rating due to its potential for remote code execution with system privileges.
How do I fix CVE-2024-7987?
To remediate CVE-2024-7987, update the Rockwell Automation ThinManager ThinServer to the latest version provided by the vendor.
What software is affected by CVE-2024-7987?
CVE-2024-7987 specifically affects Rockwell Automation ThinManager ThinServer.
Can CVE-2024-7987 be exploited remotely?
Yes, CVE-2024-7987 can be exploited remotely by a threat actor to execute arbitrary code.
What are the potential impacts of CVE-2024-7987?
The potential impacts of CVE-2024-7987 include unauthorized access and execution of malicious code within the affected system.