ID

VAR-202408-2335


CVE

CVE-2024-7987


TITLE

Rockwell Automation ThinManager ThinServer Arbitrary File Creation Privilege Escalation Vulnerability

Trust: 0.7

sources: ZDI: ZDI-24-1157

DESCRIPTION

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to upload arbitrary files. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.The specific flaw exists within the ThinServer service which listens on TCP port 2031 by default. The issue results from the lack of proper access controls set on resources used by the service. Rockwell Automation ThinManager is a thin client management software from Rockwell Automation, USA

Trust: 2.07

sources: NVD: CVE-2024-7987 // ZDI: ZDI-24-1157 // CNVD: CNVD-2024-46734

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2024-46734

AFFECTED PRODUCTS

vendor:rockwell automationmodel:thinmanagerscope: - version: -

Trust: 0.7

vendor:rockwellmodel:automation thinmanager thinserverscope:gteversion:1.1.0,<=11.1.7

Trust: 0.6

vendor:rockwellmodel:automation thinmanager thinserverscope:gteversion:11.2.0,<=11.2.8

Trust: 0.6

vendor:rockwellmodel:automation thinmanager thinserverscope:gteversion:12.0.0,<=12.0.6

Trust: 0.6

vendor:rockwellmodel:automation thinmanager thinserverscope:gteversion:12.1.0,<=12.1.7

Trust: 0.6

vendor:rockwellmodel:automation thinmanager thinserverscope:gteversion:13.0.0,<=13.0.4

Trust: 0.6

vendor:rockwellmodel:automation thinmanager thinserverscope:gteversion:13.1.0,<=13.1.2

Trust: 0.6

vendor:rockwellmodel:automation thinmanager thinserverscope:gteversion:13.2.0,<=13.2.1

Trust: 0.6

sources: ZDI: ZDI-24-1157 // CNVD: CNVD-2024-46734

CVSS

SEVERITY

CVSSV2

CVSSV3

PSIRT@rockwellautomation.com: CVE-2024-7987
value: HIGH

Trust: 1.0

ZDI: CVE-2024-7987
value: HIGH

Trust: 0.7

CNVD: CNVD-2024-46734
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2024-46734
severity: MEDIUM
baseScore: 6.8
vectorString: AV:L/AC:L/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

ZDI: CVE-2024-7987
baseSeverity: HIGH
baseScore: 7.8
vectorString: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 0.7

sources: ZDI: ZDI-24-1157 // CNVD: CNVD-2024-46734 // NVD: CVE-2024-7987

PROBLEMTYPE DATA

problemtype:CWE-434

Trust: 1.0

sources: NVD: CVE-2024-7987

PATCH

title:Rockwell Automation has issued an update to correct this vulnerability.url:https://www.rockwellautomation.com/en-ca/trust-center/security-advisories/advisory.SD1692.html

Trust: 0.7

title:Patch for Rockwell Automation ThinManager ThinServer Remote Code Execution Vulnerability (CNVD-2024-46734)url:https://www.cnvd.org.cn/patchInfo/show/634611

Trust: 0.6

sources: ZDI: ZDI-24-1157 // CNVD: CNVD-2024-46734

EXTERNAL IDS

db:NVDid:CVE-2024-7987

Trust: 2.3

db:ZDIid:ZDI-24-1157

Trust: 1.3

db:ZDI_CANid:ZDI-CAN-24006

Trust: 0.7

db:CNVDid:CNVD-2024-46734

Trust: 0.6

sources: ZDI: ZDI-24-1157 // CNVD: CNVD-2024-46734 // NVD: CVE-2024-7987

REFERENCES

url:https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.sd1692.html

Trust: 1.0

url:https://www.rockwellautomation.com/en-ca/trust-center/security-advisories/advisory.sd1692.html

Trust: 0.7

url:https://www.zerodayinitiative.com/advisories/zdi-24-1157/

Trust: 0.6

sources: ZDI: ZDI-24-1157 // CNVD: CNVD-2024-46734 // NVD: CVE-2024-7987

CREDITS

Nicholas Zubrisky (@NZubrisky) of Trend Micro Security Research

Trust: 0.7

sources: ZDI: ZDI-24-1157

SOURCES

db:ZDIid:ZDI-24-1157
db:CNVDid:CNVD-2024-46734
db:NVDid:CVE-2024-7987

LAST UPDATE DATE

2024-12-21T23:01:33.661000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-24-1157date:2024-08-22T00:00:00
db:CNVDid:CNVD-2024-46734date:2024-12-02T00:00:00
db:NVDid:CVE-2024-7987date:2024-08-26T18:35:13.553

SOURCES RELEASE DATE

db:ZDIid:ZDI-24-1157date:2024-08-22T00:00:00
db:CNVDid:CNVD-2024-46734date:2024-12-02T00:00:00
db:NVDid:CVE-2024-7987date:2024-08-26T15:15:09.047