VendorsRockwell Automationthinmanagerall versions
Vulnerabilities

Rockwell Automation Thinmanager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2022-38742
Rockwell Automation ThinManager Software Vulnerable to Arbitrary Code Execution and Denial-Of-Service Attack
Published 2022-09-23 · Modified
9.8EPSS 0.222
CVE-2024-10386
Rockwell Automation FactoryTalk ThinManager Authentication Vulnerability
Published 2024-10-25 · Analyzed
9.8EPSS 0.193
CVE-2023-27855
Rockwell Automation ThinManager ThinServer Path Traversal Upload
Published 2023-03-21 · Modified
9.8EPSS 0.135
CVE-2024-5988
Rockwell Automation ThinManager® ThinServer™ Improper Input Validation Vulnerability
Published 2024-06-25 · Modified
9.8EPSS 0.027
CVE-2024-5989
Rockwell Automation ThinManager® ThinServer™ Improper Input Validation Vulnerability
Published 2024-06-25 · Modified
9.8EPSS 0.024
CVE-2024-45826
ThinManager® Code Execution Vulnerability
Published 2024-09-12 · Analyzed
8.8EPSS 0.123
CVE-2025-9065
Rockwell Automation ThinManager® Server-Side Request Forgery Vulnerability
Published 2025-09-09 · Analyzed
8.8EPSS 0.005
CVE-2024-10387
Rockwell Automation FactoryTalk ThinManager Denial-of-Service Vulnerability
Published 2024-10-25 · Analyzed
8.7EPSS 0.080
CVE-2024-5990
ThinManager® ThinServer™ Improper Input Validation Vulnerability
Published 2024-06-25 · Modified
8.7EPSS 0.023
CVE-2025-3618
Local Privilege Escalation Vulnerability
Published 2025-04-15 · Analyzed
8.5EPSS 0.018
CVE-2025-3617
Local Privilege Escalation in ThinManager®
Published 2025-04-15 · Analyzed
8.5EPSS 0.003
CVE-2023-27856
Rockwell Automation ThinManager ThinServer Path Traversal Download
Published 2023-03-21 · Modified
7.5EPSS 0.772
CVE-2023-27857
Rockwell Automation ThinManager ThinServer Heap-Based Buffer Overflow
Published 2023-03-22 · Modified
7.5EPSS 0.183
CVE-2023-2913
Rockwell Automation ThinManager ThinServer Path Traversal Vulnerability
Published 2023-07-18 · Modified
7.5EPSS 0.024
CVE-2023-2443
Rockwell Automation ThinManager product allows the use of medium strength ciphers.  If the client requests an insecure cipher, a malicious actor could potentially decrypt traffic sent between the client and server API.
Published 2023-05-11 · Modified
7.5EPSS 0.007
CVE-2024-7986
Rockwell Automation ThinManager® ThinServer™ Information Disclosure
Published 2024-08-23 · Analyzed
7.5EPSS 0.006