A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that points to the target directory.
| Software | From | Fixed in |
|---|---|---|
| rockwellautomation / thinmanager | 11.1.0 | 11.1.8 |
| rockwellautomation / thinmanager | 11.2.0 | 11.2.9 |
| rockwellautomation / thinmanager | 12.0.0 | 12.0.7 |
| rockwellautomation / thinmanager | 12.1.0 | 12.1.8 |
| rockwellautomation / thinmanager | 13.0.0 | 13.0.5 |
| rockwellautomation / thinmanager | 13.1.0 | 13.1.3 |
| rockwellautomation / thinmanager | 13.2.0 | 13.2.2 |