Rockwell Automation ThinManager
Plan PatchCVSS 8.1ICS-CERT ICSA-26-204-05Jul 14, 2026
Rockwell Automation
Summary
Rockwell ThinManager contains a path traversal vulnerability in its API that allows unauthenticated access to files outside the intended application directory. An attacker could read or modify sensitive files including configuration data, credentials, or scripts that manage terminal access and industrial control system connections. The vulnerability affects all versions of ThinManager, and Rockwell has not released a patch.
What this means
What could happen
An attacker could read or modify files outside the intended application directory on ThinManager servers, potentially exposing sensitive configuration data, credentials, or scripts that control terminal access and device management for industrial HMI systems.
Who's at risk
Water and electric utilities operating Rockwell ThinManager-based HMI terminals and thin client systems for remote monitoring and control of SCADA infrastructure, programmable logic controllers (PLCs), and operator workstations.
How it could be exploited
An attacker with network access to the ThinManager API could craft a path traversal request using directory traversal sequences (e.g., "../") to access files outside the restricted directory. This could allow reading configuration files, credential stores, or system scripts, or modifying them to alter device behavior or gain further access.
Prerequisites
- Network access to ThinManager API port (typically 80/443)
- No authentication required to access vulnerable API endpoint
remotely exploitableno authentication requiredlow complexityno patch availableaffects control system management layer
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (5)
4 with fix1 EOL
ProductAffected VersionsFix Status
ThinManagerAll versionsNo fix (EOL)
ThinManager: >=13.0.0|<13.0.7≥ 13.0.0|<13.0.7Fix available
ThinManager: >=13.1.0|<13.1.5≥ 13.1.0|<13.1.5Fix available
ThinManager: >=13.2.0|<13.2.4≥ 13.2.0|<13.2.4Fix available
ThinManager: >=14.0.0|<14.0.2≥ 14.0.0|<14.0.2Fix available
Remediation & Mitigation
0/4
Do now
0/3ThinManager
HARDENINGRestrict network access to ThinManager API ports using firewall rules—allow only connections from authorized workstations and HMI systems
HARDENINGImplement API authentication and validation controls if available in your ThinManager configuration
HARDENINGMonitor ThinManager server logs for suspicious API requests containing path traversal patterns (e.g., requests with '../' or encoded variants)
Mitigations - no patch available
0/1ThinManager has reached End of Life. The vendor will not release a patch. Apply the following compensating controls:
HARDENINGSegment ThinManager servers from untrusted networks using network access control lists (ACLs)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/a6c91cda-5686-4109-8b7f-9c913a00ff44Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.