Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mcpp-jhwq-85qq

Опубликовано: 26 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to upload arbitrary files.

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to upload arbitrary files.

EPSS

Процентиль: 34%
0.00138
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.8
nvd
больше 1 года назад

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to upload arbitrary files.

CVSS3: 7.8
fstec
почти 2 года назад

Уязвимость компонента ThinServer платформы для централизованного управления приложениями Rockwell Automation ThinManager, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 34%
0.00138
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-434