ZDI-CAN-24002: ZDI-24-1156: Rockwell Automation ThinManager ThinServer Arbitrary File Read Information Disclosure Vulnerability
This vulnerability allows local attackers to read arbitrary files on affected installations of Rockwell Automation ThinManager. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2024-7986.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24002?
ZDI-CAN-24002 has been rated as a high severity vulnerability due to the potential for local file reading by attackers.
How do I fix ZDI-CAN-24002?
To address ZDI-CAN-24002, apply the latest security patches provided by Rockwell Automation for ThinManager.
What are the conditions required to exploit ZDI-CAN-24002?
Exploiting ZDI-CAN-24002 requires that the attacker has the ability to execute low-privileged code on the affected system.
What impact does ZDI-CAN-24002 have on affected systems?
ZDI-CAN-24002 enables local attackers to read arbitrary files, which can lead to unauthorized access to sensitive information.
Which software is affected by ZDI-CAN-24002?
ZDI-CAN-24002 specifically affects Rockwell Automation ThinManager installations.