CVE-2025-3617

A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary folder causing the Access Control Entry of the directory to inherit permissions from the parent directory. If exploited, a threat actor could inherit elevated privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*

History

14 Jul 2025, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:rockwellautomation:thinmanager:*:*:*:*:*:*:*:*
References () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1727.html - () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1727.html - Vendor Advisory
First Time Rockwellautomation thinmanager
Rockwellautomation

15 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 18:15

Updated : 2025-07-14 19:16


NVD link : CVE-2025-3617

Mitre link : CVE-2025-3617


JSON object : View

Products Affected

rockwellautomation

  • thinmanager
CWE

No CWE.