A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™
that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to upload arbitrary files.
CVSS
No CVSS.
References
Configurations
No configuration.
History
26 Aug 2024, 18:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-434 |
26 Aug 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-26 15:15
Updated : 2024-08-26 18:35
NVD link : CVE-2024-7987
Mitre link : CVE-2024-7987
CVE.ORG link : CVE-2024-7987
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type