Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.
| Software | From | Fixed in |
|---|---|---|
| rockwellautomation / thinserver | 13.2.0 | 13.2.2 |
| rockwellautomation / thinserver | 13.1.0 | 13.1.3 |
| rockwellautomation / thinserver | 13.0.0 | 13.0.5 |
| rockwellautomation / thinserver | 12.1.0 | 12.1.8 |
| rockwellautomation / thinserver | 12.0.0 | 12.0.7 |
| rockwellautomation / thinserver | 11.2.0 | 11.2.9 |
| rockwellautomation / thinserver | 11.1.0 | 11.1.8 |
| rockwellautomation / thinmanager | 11.1.0 | 11.1.8 |
| rockwellautomation / thinmanager | 11.2.0 | 11.2.9 |
| rockwellautomation / thinmanager | 12.0.0 | 12.0.7 |
| rockwellautomation / thinmanager | 12.1.0 | 12.1.8 |
| rockwellautomation / thinmanager | 13.0.0 | 13.0.5 |
| rockwellautomation / thinmanager | 13.1.0 | 13.1.3 |
| rockwellautomation / thinmanager | 13.2.0 | 13.2.2 |