QID 591294

Date Published: 2023-01-19

QID 591294: Rockwell Automation ThinManager ThinServer Heap-based Buffer Overflow Vulnerability (ICSA-22-270-03)

ThinManager ThinServer is a server-side configuration, management, and hardware enabling software for Terminal Services based thin client systems.

AFFECTED PRODUCTS
Rockwell Automation reported these vulnerabilities to affect the following versions of ThinManager ThinServer, an automation development tool: Versions 11.0.0 through 11.0.4
Versions 11.1.0 through 11.1.4
Versions 11.2.0 through 11.2.5
Versions 12.0.0 through 12.0.2
Versions 12.1.0 through 12.1.3
Version 13.0.0

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys HKEY_LOCAL_MACHINE\SOFTWARE\Automation Control Products\ThinManager

Successful exploitation of this vulnerability could lead to the software crashing; a buffer overflow condition may allow remote code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to Rockwell Automation MITIGATIONS section ICSA-22-270-03 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591294

    Software Advisories
    Advisory ID Software Component Link
    ICSA-22-270-03 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-270-03