Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-10386 PoC — Rockwell Automation FactoryTalk ThinManager Authentication Vulnerability

Source
Associated Vulnerability
Title:Rockwell Automation FactoryTalk ThinManager Authentication Vulnerability (CVE-2024-10386)
Description:CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in database manipulation.
Readme
# CVE-2024-10386: Missing Authentication for Critical Function (CWE-306)

## Overview

CVE-2024-10386 significantly impacts Rockwell Automation's FactoryTalk ThinManager, a crucial product for industrial automation. This vulnerability poses a substantial risk due to its potential to allow unauthorized users to manipulate databases through network access.


## Details
+ **CVE ID:** CVE-2024-10386
+ **Published:** 2024-10-25
+ **Impact:** Critical
+ **Exploit Availability:** Not public, only private.
+ **CVSS:** 9.3


## Vulnerability Description

The vulnerability allows a threat actor with network access to send crafted messages to the device, resulting in database manipulation.


## Affected Versions

This vulnerability affects **Rockwell Automation ThinManager software versions 11.2.0 up to (but not including) 11.2.10, 12.0.0 up to 12.0.8, 12.1.0 up to 12.1.9, 13.0.0 up to 13.0.6, 13.1.0 up to 13.1.4, 13.2.0 up to 13.2.3, and version 14.0.0.**

## Usage
```
python CVE-2024-10386.py -h 10.10.10.10 -c 'uname -a'
```

## Contact
For inquiries, please contact zetraxz@thesecure.biz

## Exploit
**[Download](https://ur0.jp/f7tKh)**
File Snapshot

[4.0K] /data/pocs/e7aba580c1be4a00146a4900bcf70a9c4d407a3d └── [1.1K] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →