Machine-generated analysis · WAYSCloud LLM
ThinManager versions prior to 13.0.8, 13.1.6, 13.2.5, and 14.0.3 are vulnerable to an authenticated path-traversal flaw.
Context
The advisory concerns Rockwell Automation ThinManager software. It states that an authenticated attacker could exploit a path-traversal issue to write arbitrary files to restricted system directories outside the application’s intended directory. The vulnerability affects versions 13.0.0-13.0.6, 13.1.0-13.1.4, 13.2.0-13.2.3, and 14.0.0-14.0.2, which are deployed worldwide across multiple critical infrastructure sectors.
Operator considerations
Check: inventory ThinManager installations and verify version numbers.
Isolate: segment ThinManager network interfaces or restrict access to trusted hosts.
Patch: upgrade affected installations to ThinManager 13.0.8, 13.1.6, 13.2.5, or 14.0.3 as applicable.
Log: monitor API file-save operations and watch for unexpected writes to system directories.
Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory.
The following versions of Rockwell Automation ThinManager are affected:
ThinManager >=13.0.0|=13.1.0|=13.2.0|=14.0.0|
Read the full advisory on CISA →