Rockwell Automation FactoryTalk ThinManager Vulnerabilities
ID: d718655a-acf2-596e-bf3e-49a2f8e60e71
STIX ID: report--d718655a-acf2-596e-bf3e-49a2f8e60e71
Feed Name: Cyble Blog
CISA has issued advisory ICSA-24-305-01 for two severe vulnerabilities in Rockwell Automation FactoryTalk ThinManager—CVE-2024-10386 (Missing Authentication for Critical Function, CVSS v3.1 9.8) and CVE-2024-10387 (Out-of-Bounds Read, CVSS v3.1 7.5 / CVSS v4 8.7)—affecting multiple FactoryTalk ThinManager versions; network-accessible attackers could manipulate databases or cause DoS, patches are available, and CISA recommends restricting TCP/2031, network segmentation, and applying Rockwell's security guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
