References https://support.rockwellautomation.com/app/answers/answer_view/a_id/1140160/~/thinmanager%C2%AE-thinserver%E2%84%A2-path-traversal-vulnerability- https://support.rockwellautomation.com/app/answers/answer_view/a_id/1138640/~/thinmanager-software-path-traversal-and-denial-of-service-attack- https://support.rockwellautomation.com/app/answers/answer_view/a_id/1140471/~/thinmanager%C2%AE-thinserver%E2%84%A2-input-validation-vulnerabilities- https://www.tenable.com/plugins/nessus/173822 https://app.opencve.io/cve/?vendor=rockwellautomation&product=thinmanager_thinserver https://support.rockwellautomation.com/app/answers/answer_view/a_id/1138754/~/thinmanager-release-notes-for-13.0-sp2- https://support.rockwellautomation.com/app/answers/answer_view/a_id/1138751/~/thinmanager-release-notes-for-12.1-sp6- https://support.rockwellautomation.com/app/answers/answer_view/a_id/1151761/~/thinmanager-release-notes-for-11.2-sp8- https://www.cve.org/CVERecord?id=CVE-2023-27855 https://www.cve.org/CVERecord?id=CVE-2023-2915 https://www.mangancyber.com/rockwell-thinmanager-thinserver-vulnerability/ https://github.com/advisories/GHSA-j8wc-x537-84cv https://github.com/advisories/GHSA-9hjj-m2fc-f62r
Related VulnerabilitiesFrappe /api/method/frappe.automation.doctype.auto_repeat.auto_repeat.generate_message_preview SQL 注入漏洞(CVE-2025-68929)Ksenia Security Lares 4.0 Home Automation 安全漏洞PoCCVE-2021-41291: ECOA Building Automation System - Directory Traversal Content DisclosurePoCCVE-2021-41293: ECOA Building Automation System - Arbitrary File RetrievalPoCCVE-2022-22972: VMware Workspace ONE Access/Identity Manager/vRealize Automation - Authentication BypassPoCCVE-2022-26833: Open Automation Software OAS Platform V16.00.0121 - Missing AuthenticationPoCCVE-2024-6922: Automation Anywhere Automation 360 - Server-Side Request ForgeryPoCCVE-2024-9186: Automation By Autonami < 3.3.0 - SQL InjectionPoCCVE-2025-1562: Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access ControlPoCCVE-2025-3102: SureTriggers – All-in-One Automation Platform ≤ 1.0.78 - Authentication BypassPoCCVE-2020-21998: HomeAutomation 3.3.2 - Open RedirectPoCtcpconfig: Rockwell Automation TCP/IP Configuration Information - Detect