"value":"The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists when the ThinManager software processes a certain function. If exploited, an unauthenticated remote threat actor can delete arbitrary files with system privileges. A malicious user could exploit this vulnerability by sending a specifically crafted synchronization protocol message resulting in a denial-of-service condition. "
"value":"\n\n<ul><li>Update to the corrected software versions.</li><li>Limit remote access for TCP Port 2031 to known thin clients and ThinManager servers.</li></ul>"
}
],
"value":"\n * Update to the corrected software versions.\n * Limit remote access for TCP Port 2031 to known thin clients and ThinManager servers.\n\n\n"
}
],
"credits":[
{
"lang":"en",
"value":"This vulnerability was reported to Rockwell Automation by Tenable Network Security."