ZDI-CAN-25872: ZDI-25-289: Rockwell Automation ThinManager ThinServer Null Pointer Dereference Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Rockwell Automation ThinManager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-3618.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25872?
ZDI-CAN-25872 has been assigned a CVSS rating of 7.5, indicating a high severity vulnerability.
How do I fix ZDI-CAN-25872?
To mitigate ZDI-CAN-25872, ensure that you apply the latest patches provided by Rockwell Automation for ThinManager.
Who can exploit ZDI-CAN-25872?
ZDI-CAN-25872 can be exploited by remote attackers without the need for authentication.
What type of attack does ZDI-CAN-25872 enable?
ZDI-CAN-25872 allows attackers to create a denial-of-service condition on affected installations.
Which software is affected by ZDI-CAN-25872?
ZDI-CAN-25872 affects Rockwell Automation ThinManager, particularly its ThinServer component.