Critical severity9.8NVD Advisory· Published Jun 25, 2024· Updated Jun 17, 2026
CVE-2024-5989
CVE-2024-5989
Description
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*range: >=11.1.0,<11.1.8
- (no CPE)range: 11.0.0
- cpe:2.3:a:rockwellautomation:thinserver:*:*:*:*:*:*:*:*Range: >=11.1.0,<11.1.8
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.