« Volver al listado

CVE-2024-7987

Estado: AnalizadaAlta (8.5)—

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to upload arbitrary files.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-7987",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-7987",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-26T17:20:29.756565Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "PSIRT@rockwellautomation.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.5,
          "Automatable": "NOT_DEFINED",
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "PSIRT@rockwellautomation.com",
      "affectedData": [
        {
          "vendor": "Rockwell Automation",
          "product": "ThinManager® ThinServer™",
          "versions": [
            {
              "status": "affected",
              "version": "11.1.0-11.1.7 11.2.0-11.2.8 12.0.0-12.0.6 12.1.0-12.1.7 13.0.0-13.0.4 13.1.0-13.1.2 13.2.0-13.2.1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*"
          ],
          "vendor": "rockwellautomation",
          "product": "thinmanager_thinserver",
          "versions": [
            {
              "status": "affected",
              "version": "11.1.0",
              "versionType": "custom",
              "lessThanOrEqual": "11.1.7"
            },
            {
              "status": "affected",
              "version": "11.2.0",
              "versionType": "custom",
              "lessThanOrEqual": "11.2.8"
            },
            {
              "status": "affected",
              "version": "12.0.0",
              "versionType": "custom",
              "lessThanOrEqual": "12.0.6"
            },
            {
              "status": "affected",
              "version": "12.1.0",
              "versionType": "custom",
              "lessThanOrEqual": "12.1.7"
            },
            {
              "status": "affected",
              "version": "13.0.0",
              "versionType": "custom",
              "lessThanOrEqual": "13.0.4"
            },
            {
              "status": "affected",
              "version": "13.1.0",
              "versionType": "custom",
              "lessThanOrEqual": "13.1.2"
            },
            {
              "status": "affected",
              "version": "13.2.0",
              "versionType": "custom",
              "lessThanOrEqual": "13.2.1"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-08-26T15:15:09.047",
  "references": [
    {
      "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1692.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT@rockwellautomation.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™\nthat allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to upload arbitrary files."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de ejecución remota de código en ThinManager® ThinServer™ de Rockwell Automation que permite a un actor de amenazas ejecutar código arbitrario con privilegios de System. Para explotar esta vulnerabilidad, un actor de amenazas debe abusar del servicio ThinServer™ creando una unión y utilizándola para cargar archivos arbitrarios."
    }
  ],
  "lastModified": "2026-06-17T08:21:37.313",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F628C11D-148F-40E7-96D6-5AA4C6870E9E",
              "versionEndExcluding": "11.1.8",
              "versionStartIncluding": "11.1.0"
            },
            {
              "criteria": "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4949C9C3-5978-425B-99F0-DA4FB74690C5",
              "versionEndExcluding": "11.2.9",
              "versionStartIncluding": "11.2.0"
            },
            {
              "criteria": "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA2CD8E4-889B-48EA-9D06-B599DC3D6ACA",
              "versionEndExcluding": "12.0.7",
              "versionStartIncluding": "12.0.0"
            },
            {
              "criteria": "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8C4E638-E1E6-4BE9-B498-4600CE6C1CD7",
              "versionEndExcluding": "12.1.8",
              "versionStartIncluding": "12.1.0"
            },
            {
              "criteria": "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0797A814-6983-4686-B639-EDA1E2ADFBF0",
              "versionEndExcluding": "13.0.5",
              "versionStartIncluding": "13.0.0"
            },
            {
              "criteria": "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7100E69-4C7E-4194-98A4-ECFE9C4356F0",
              "versionEndExcluding": "13.1.3",
              "versionStartIncluding": "13.1.0"
            },
            {
              "criteria": "cpe:2.3:a:rockwellautomation:thinmanager_thinserver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C99672F3-B57F-40C1-9D02-79D906D47D9A",
              "versionEndExcluding": "13.2.2",
              "versionStartIncluding": "13.2.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "PSIRT@rockwellautomation.com"
}