PatchSiren cyber security CVE debrief
CVE-2024-5990 Rockwell Automation CVE debrief
A vulnerability in Rockwell Automation ThinManager ThinServer allows unauthenticated remote attackers to cause denial-of-service conditions by sending malicious messages to a monitor thread. The flaw stems from improper input validation and affects multiple versions of ThinServer from 11.1.0 through 13.1.0. Rockwell Automation has released corrected versions for all affected branches.
- Vendor
- Rockwell Automation
- Product
- ThinManager ThinServer
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-07-11
- Original CVE updated
- 2024-07-11
- Advisory published
- 2024-07-11
- Advisory updated
- 2024-07-11
Who should care
Organizations operating Rockwell Automation ThinManager ThinServer in industrial environments, particularly those with remote thin client deployments or exposed ThinServer instances. Critical infrastructure operators, manufacturing facilities, and any OT environments where ThinManager availability is essential for operational continuity.
Technical summary
CVE-2024-5990 is an improper input validation vulnerability in Rockwell Automation ThinManager ThinServer. An unauthenticated attacker can send a crafted message to a monitor thread listening on TCP port 2031, causing a denial-of-service condition on the affected device. The vulnerability is network-exploitable with low attack complexity and requires no privileges or user interaction. CVSS 3.1 score: 7.5 (HIGH). Affected versions include 11.1.0, 11.2.0, 12.0.0, 12.1.0, 13.0.0, and 13.1.0. Rockwell Automation has released patched versions for all affected branches.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade ThinManager ThinServer to corrected versions: 11.1.8, 11.2.9, 12.0.7, 12.1.8, 13.0.5, 13.1.3, or 13.2.2 via the ThinManager Downloads Site
- Restrict network access to TCP port 2031 to only known thin clients and ThinManager servers
- Apply Rockwell Automation's security best practices for industrial control systems
- Monitor ThinServer availability and implement redundancy where critical operations depend on ThinManager infrastructure
Evidence notes
CISA published advisory ICSA-24-193-18 on 2024-07-11 identifying this vulnerability. The advisory confirms unauthenticated network access to TCP port 2031 is sufficient to trigger the denial-of-service condition. Rockwell Automation has provided corrected software versions across all affected release branches.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-5990 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-5990
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-5990 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-5990
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-193-18.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-193-18
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.