Rockwell Automation ThinManager
Rockwell Automation has issued a security advisory regarding a path traversal vulnerability in its ThinManager software. This vulnerability allows an authenticated attacker to write arbitrary files to restricted system directories outside the application's intended directory. Affected versions include ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, and >=14.0.0|<14.0.2. CISA recommends immediate upgrading to a patched version or implementing Rockwell Automation's security best practices to mitigate the risk.
Rockwell Automation has issued a security advisory regarding a critical path traversal vulnerability within its ThinManager software. This vulnerability presents a significant risk as it enables an authenticated attacker to write arbitrary files to restricted system directories beyond the application's intended scope. The affected versions of ThinManager include: ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, and >=14.0.0|<14.0.2. CISA recommends that organizations immediately upgrade to one of the corrected versions to address this issue. Rockwell Automation has provided vendor fixes and security best practices to assist with remediation. The vulnerability is classified as a critical risk due to its potential for malicious file creation and system compromise. The advisory highlights the importance of minimizing network exposure for control system devices and isolating them from business networks. CISA also recommends utilizing more secure remote access methods, such as VPNs, while recognizing that VPNs themselves can have vulnerabilities. Organizations are urged to perform thorough impact analysis and risk assessments before deploying any defensive measures. Furthermore, CISA encourages proactive cybersecurity strategies for Industrial Control Systems (ICS) assets and provides resources on ICS security best practices, including a technical information paper on targeted cyber intrusion detection and mitigation strategies (ICS-TIP-12-146-01B).