Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vcw7-84v8-pfqh

Опубликовано: 23 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 6.8

Описание

A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that points to the target directory.

A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that points to the target directory.

EPSS

Процентиль: 34%
0.00141
Низкий

6.8 Medium

CVSS4

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that points to the target directory.

CVSS3: 5.5
fstec
почти 2 года назад

Уязвимость компонента ThinServer платформы для централизованного управления приложениями Rockwell Automation ThinManager, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 34%
0.00141
Низкий

6.8 Medium

CVSS4

Дефекты

CWE-732