CVE-2025-9065: Rockwell Automation ThinManager® Server-Side Request Forgery Vulnerability
A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing the ThinServer® service account NTLM hash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9065?
CVE-2025-9065 is classified as a high-severity vulnerability due to its potential impact on confidential information.
How do I fix CVE-2025-9065?
To resolve CVE-2025-9065, apply the latest security patch provided by Rockwell Automation for ThinManager software.
Who is affected by CVE-2025-9065?
CVE-2025-9065 affects users of Rockwell Automation ThinManager software, particularly those utilizing SMB paths.
What kind of attack is possible with CVE-2025-9065?
CVE-2025-9065 allows authenticated attackers to perform server-side request forgery attacks exploiting input sanitization weaknesses.
What is the main cause of CVE-2025-9065?
The main cause of CVE-2025-9065 is a lack of proper input sanitization in the Rockwell Automation ThinManager software.