Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7mhq-hm3w-mqpr

Опубликовано: 09 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.8

Описание

A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing the ThinServer® service account NTLM hash.

A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing the ThinServer® service account NTLM hash.

EPSS

Процентиль: 7%
0.00026
Низкий

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-610
CWE-918

Связанные уязвимости

CVSS3: 8.8
nvd
5 месяцев назад

A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing the ThinServer® service account NTLM hash.

EPSS

Процентиль: 7%
0.00026
Низкий

8.6 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-610
CWE-918