CVE-2024-10387 is a Denial-of-Service vulnerability affecting Rockwell Automation ThinManager products. An unauthenticated attacker with network access can send specially crafted messages to the device, leading to a denial of service. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network without user interaction. While there is no known active exploitation, public exploit code, or KEV listing, it has garnered some community discussion and media coverage, including a CISA warning.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.2.0, < 11.2.10CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:* | ||
>= 12.0.0, < 12.0.8CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:* | ||
>= 12.1.0, < 12.1.9CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:* | ||
>= 13.0.0, < 13.0.6CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:* | ||
>= 13.1.0, <= 13.1.4CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Rockwell Automation ThinManager ThinServer.exe Monitor Thread Multiple Vulnerabilities
Oct 25, 2024Rockwell Automation ThinManager ThinServer.exe Monitor Thread Multiple Vulnerabilities
Oct 25, 2024Rockwell Automation ThinManager ThinServer.exe Monitor Thread Multiple Vulnerabilities
Oct 25, 2024Rockwell Automation ThinManager ThinServer.exe Monitor Thread Multiple Vulnerabilities
Oct 25, 2024