Rockwell Automation ThinManager Vulnerability Allows Arbitrary File Writes
A vulnerability in Rockwell Automation ThinManager allows an authenticated attacker to write arbitrary files to restricted system directories. The affected versions are ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, and >=14.0.0|<14.0.2. Users are advis…
Intelligence analysis by Llama
A path traversal security issue exists in Rockwell Automation ThinManager software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory.
Imagine you have a computer system that controls important things like power plants or water treatment plants. A hacker could use a special trick to write bad code on the system, which could make it do bad things. To fix this, the company that made the system needs to update it so that the hacker can't use this trick.
Analysis
Background
The vulnerability in Rockwell Automation ThinManager is a critical issue that affects various critical infrastructure sectors. The affected software allows an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. This could potentially lead to unauthorized access, data breaches, or system compromise.
Affected Products
The affected versions of Rockwell Automation ThinManager are ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, and >=14.0.0|<14.0.2. Users are advised to upgrade to the corrected versions or use Rockwell Automation's security best practices.
Mitigation
CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
Additional Guidance
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Key points
- A vulnerability in Rockwell Automation ThinManager allows an authenticated attacker to write arbitrary files to restricted system directories.
- The affected versions are ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, and >=14.0.0|<14.0.2.
- Users are advised to upgrade to the corrected versions or use Rockwell Automation's security best practices.
- CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.
If users upgrade to the corrected versions of Rockwell Automation ThinManager or use the company's security best practices, they can minimize the risk of exploitation of this vulnerability. This will help ensure the security of control systems and prevent potential unauthorized access or data breaches.
If users do not address this vulnerability, an authenticated attacker could exploit it to write arbitrary files to restricted system directories, potentially leading to unauthorized access, data breaches, or system compromise.



