Local Command Injection in Siemens SIMATIC RTLS Locating Manager
CVE-2020-10049
7.3HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 9 September 2020
What is CVE-2020-10049?
A security vulnerability exists in the SIMATIC RTLS Locating Manager that allows a local attacker to execute arbitrary commands through the start-stop scripts for services. This occurs when the services are started or stopped interactively by system administrators, creating a potential risk for system integrity. Users of versions prior to V2.10.2 are advised to update to mitigate this security flaw.
Affected Version(s)
SIMATIC RTLS Locating Manager All versions < V2.10.2