Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ThinManager® - Path Traversal via API
Vulnerability Description
A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Rockwell Automation FactoryTalk ThinManager 路径遍历漏洞
Vulnerability Description
Rockwell Automation FactoryTalk ThinManager是美国Rockwell Automation基金会的一款工厂可视化管理软件。 Rockwell Automation FactoryTalk ThinManager存在路径遍历漏洞,该漏洞源于API中文件保存操作限制不当,可能导致经过身份验证的攻击者将任意文件写入应用程序预期目录之外的受限系统目录。以下版本受到影响:13.0.0版本至13.0.7版本、13.1.0版本至13.1.5版本、13.2.0版本至13.2.4版本
CVSS Information
N/A
Vulnerability Type
N/A