CVE-2025-3618: Rockwellautomation Thinmanager

Medium severity, CVSS 5.5. EPSS: 1.8% chance of exploitation in the next 30 days.

A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify the outcome of memory allocation while processing Type 18 messages. If exploited, a threat actor could cause a denial-of-service on the target software.

Affected products

  • Rockwellautomation Thinmanager: before 11.2.11 (fixed in 11.2.11); from 12.0.0, before 12.0.9 (fixed in 12.0.9); from 12.1.0, before 12.1.10 (fixed in 12.1.10); from 13.0.0, before 13.0.7 (fixed in 13.0.7); from 13.1.0, before 13.1.5 (fixed in 13.1.5); from 13.2.0, before 13.2.4 (fixed in 13.2.4); …

Published 2025-04-15. Last modified 2026-06-17.