Thinmanager
Vendor:
First CVE: Sep 23, 2022 · Active for 3 years
16
Total CVEs
More Total CVEs than 93% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Thinmanager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 23, 2022
3 years ago
Most Recent CVE
Sep 9, 2025
321 days ago
CVE Severity & Scoring
Thinmanager16 CVEs
13%
56%
31%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (12.5%)
Network14 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None16 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (31.3%)
High0 (0.0%)
None11 (68.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27856HIGH
In affected versions, path traversal exists when processing a message of type 8
in Rockwell Automation's ThinManager ThinServer.
An unauthenticated remote attacker can explo | Mar 22, 2023 | 7.5 | 71 | NO | YES |
CVE-2023-27855CRITICAL
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially explo | Mar 22, 2023 | 9.8 | 48 | NO | YES |
CVE-2024-10386CRITICAL CVE-2024-10386 IMPACT
An authentication
vulnerability exists in the affected product. The vulnerability could allow a
threat actor with network access to send crafted messages t | Oct 25, 2024 | 9.8 | 37 | NO | NO |
CVE-2022-38742CRITICAL Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifically crafted TFTP or HTTPS reque | Sep 23, 2022 | 9.8 | 34 | NO | NO |
CVE-2023-27857HIGH
In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field
in Rockwell Automation's | Mar 22, 2023 | 7.5 | 32 | NO | NO |
CVE-2024-45826HIGH CVE-2024-45826 IMPACT
Due to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® processes a crafted POST request. If e | Sep 12, 2024 | 8.8 | 30 | NO | NO |
CVE-2025-9065HIGH A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this | Sep 9, 2025 | 8.8 | 29 | NO | NO |
CVE-2024-5989CRITICAL Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution conditi | Jun 25, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-5988CRITICAL Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition | Jun 25, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-10387HIGH CVE-2024-10387 IMPACT
A Denial-of-Service
vulnerability exists in the affected product. The vulnerability could allow a
threat actor with network access to send crafted messages | Oct 25, 2024 | 7.5 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
12.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 14.0.0 | 2 | 8.7 | 12.3% | 0 | 0 |
| 13.0.1 | 2 | 8.7 | 45.3% | 0 | 2 |
| 13.0.0 | 3 | 8.3 | 36.3% | 0 | 2 |