peter bassill · operator
$ cve CVE-2024-7988 JSON

CVE-2024-7988

9.8
CRITICAL · CVSS 3.1 · EPSS 4.8% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.78% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2024-08-26
Last modified2026-06-17

Affected (1)

VendorProduct
rockwellautomationthinmanager thinserver

References

→ the Explorer  ·  watch your stack  ·  NVD