← Vulnerability feed

Vulnerability record · CVE-2024-10386 · published 25 October 2024

CVE-2024-10386: Rockwellautomation thinmanager missing authentication for critical function vulnerability

Rockwellautomation · Thinmanager

CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in database manipulation.

9.3 CVSS 4.0 Critical EPSS 19% · top 2.7% CWE-306 · Missing authentication for critical function
9.3CVSS 4.0 base score
19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in database manipulation.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-10386 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-27855Rockwellautomation thinmanager path traversal vulnerabilityIn affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote at…EPSS 13%9.8CVE-2022-38742Rockwellautomation thinmanager heap-based buffer overflow vulnerabilityRockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifica…EPSS 22%9.3CVE-2024-5989Rockwellautomation thinmanager improper input validation vulnerabilityDue to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause …EPSS 2.4%9.3CVE-2024-5988Rockwellautomation thinmanager improper input validation vulnerabilityDue to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a …EPSS 2.7%8.7CVE-2024-10387Rockwellautomation thinmanager out-of-bounds read vulnerabilityCVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow a threat actor with network acc…EPSS 8.0%8.7CVE-2024-5990Rockwellautomation thinmanager improper input validation vulnerabilityDue to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation Thin…EPSS 2.3%8.6CVE-2025-9065Rockwellautomation thinmanager server-side request forgery (ssrf) vulnerabilityA server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authentic…EPSS 0.47%8.5CVE-2025-3617Rockwellautomation thinmanager incorrect default permissions vulnerabilityA privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary f…EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2024-10386), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.