ID

VAR-202509-0772


CVE

CVE-2025-9065


TITLE

Rockwell Automation ThinManager Server Request Forgery Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-21158

DESCRIPTION

A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing the ThinServer® service account NTLM hash. Rockwell Automation ThinManager is thin client management software from Rockwell Automation. It allows thin clients to be assigned to multiple remote desktop servers simultaneously. An attacker can exploit this vulnerability to forge server-side requests

Trust: 1.44

sources: NVD: CVE-2025-9065 // CNVD: CNVD-2025-21158

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-21158

AFFECTED PRODUCTS

vendor:rockwellmodel:automation thinmanagerscope:gteversion:13.0,<=14.0

Trust: 0.6

sources: CNVD: CNVD-2025-21158

CVSS

SEVERITY

CVSSV2

CVSSV3

PSIRT@rockwellautomation.com: CVE-2025-9065
value: HIGH

Trust: 1.0

CNVD: CNVD-2025-21158
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-21158
severity: HIGH
baseScore: 8.3
vectorString: AV:N/AC:L/AU:M/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: MULTIPLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 6.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2025-21158 // NVD: CVE-2025-9065

PROBLEMTYPE DATA

problemtype:CWE-610

Trust: 1.0

sources: NVD: CVE-2025-9065

PATCH

title:Patch for Rockwell Automation ThinManager Server Request Forgery Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/731231

Trust: 0.6

sources: CNVD: CNVD-2025-21158

EXTERNAL IDS

db:NVDid:CVE-2025-9065

Trust: 1.6

db:CNVDid:CNVD-2025-21158

Trust: 0.6

sources: CNVD: CNVD-2025-21158 // NVD: CVE-2025-9065

REFERENCES

url:https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.sd1743.html

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2025-9065

Trust: 0.6

sources: CNVD: CNVD-2025-21158 // NVD: CVE-2025-9065

SOURCES

db:CNVDid:CNVD-2025-21158
db:NVDid:CVE-2025-9065

LAST UPDATE DATE

2025-10-17T23:01:36.543000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-21158date:2025-09-12T00:00:00
db:NVDid:CVE-2025-9065date:2025-09-09T16:28:43.660

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-21158date:2025-09-12T00:00:00
db:NVDid:CVE-2025-9065date:2025-09-09T13:15:32.493