Rockwell Automation ThinManager
Summary
Rockwell Automation ThinManager software is affected by a path traversal vulnerability (CVE-2026-11917) where authenticated attackers can write arbitrary files to restricted system directories. This issue impacts several versions of the software, with specific vulnerable ranges listed.
IFF Assessment
This vulnerability allows attackers to write arbitrary files to restricted system directories, which could lead to system compromise and disruption.
Severity
The CVSS score of 8.1 indicates a high severity, reflecting the potential for an authenticated attacker to write arbitrary files to restricted directories, leading to significant impact.
Defender Context
This vulnerability impacts critical infrastructure sectors, making it crucial for defenders to ensure Rockwell Automation ThinManager systems are updated to the patched versions. Attackers could leverage this path traversal to gain deeper access and potentially disrupt operations.