First published: Tue Apr 15 2025(Updated: )
A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify the outcome of memory allocation while processing Type 18 messages. If exploited, a threat actor could cause a denial-of-service on the target software.
Credit: PSIRT@rockwellautomation.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation ThinManager ThinServer |
Corrected in v11.2.11, 12.0.9, 12.1.10, 13.0.7, 13.1.5, 13.2.4, 14.0.2 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3618 has been identified as a denial-of-service vulnerability.
To mitigate CVE-2025-3618, ensure that you apply the latest security updates and patches provided by Rockwell Automation.
CVE-2025-3618 specifically affects the Rockwell Automation ThinManager software.
Exploitation of CVE-2025-3618 can lead to a denial-of-service condition, disrupting the functionality of the affected software.
Yes, a threat actor could potentially exploit CVE-2025-3618 remotely to cause service disruptions.