In affected versions, path traversal exists when processing a message of type 8
in Rockwell Automation's ThinManager ThinServer.
An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.
| Software | From | Fixed in |
|---|---|---|
| rockwellautomation / thinmanager | 6.0.0 | 10.0.2.x |
| rockwellautomation / thinmanager | 11.0.0 | 11.0.5.x |
| rockwellautomation / thinmanager | 11.1.0 | 11.1.5.x |
| rockwellautomation / thinmanager | 11.2.0 | 11.2.6.x |
| rockwellautomation / thinmanager | 12.0.0 | 12.0.4.x |
| rockwellautomation / thinmanager | 12.1.0 | 12.1.5.x |
| rockwellautomation / thinmanager | 13.0.0 | 13.0.0.x |
| rockwellautomation / thinmanager | 13.0.1 | 13.0.1.x |