logo

Rockwell Automation FactoryTalk ThinManager Vulnerabilities

ID: d718655a-acf2-596e-bf3e-49a2f8e60e71

STIX ID: report--d718655a-acf2-596e-bf3e-49a2f8e60e71

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2024-11-04

Date Updated: 2026-07-20

...
...

CISA has issued advisory ICSA-24-305-01 for two severe vulnerabilities in Rockwell Automation FactoryTalk ThinManager—CVE-2024-10386 (Missing Authentication for Critical Function, CVSS v3.1 9.8) and CVE-2024-10387 (Out-of-Bounds Read, CVSS v3.1 7.5 / CVSS v4 8.7)—affecting multiple FactoryTalk ThinManager versions; network-accessible attackers could manipulate databases or cause DoS, patches are available, and CISA recommends restricting TCP/2031, network segmentation, and applying Rockwell's security guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.