cve/2024/CVE-2024-5989.md

25 lines
1.4 KiB
Markdown
Raw Normal View History

2025-09-29 21:09:30 +02:00
### [CVE-2024-5989](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5989)
![](https://img.shields.io/static/v1?label=Product&message=ThinManager%C2%AE%20ThinServer%E2%84%A2&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=11.0.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.1.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.2.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.1.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=13.0.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=13.1.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=13.2.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-20%20Improper%20Input%20Validation&color=brightgreen)
### Description
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds