Hard-coded Key Vulnerability in SIMATIC RTLS Locating Manager Could Lead to Confidentiality and Integrity Breaches
CVE-2024-30207

10CRITICAL

Key Information:

Vendor
Siemens
Status
Simatic Rtls Locating Manager
Vendor
CVE Published:
14 May 2024

Summary

A vulnerability has been identified in the SIMATIC RTLS Locating Manager products from Siemens. This issue affects several versions prior to V3.0.1.1. The vulnerability arises from the use of symmetric cryptography that relies on a hard-coded key, which is employed to secure communication between client and server. Attackers with knowledge of this key can potentially intercept communications, leading to a compromise of confidentiality and integrity, ultimately affecting system availability. To exploit this vulnerability, an attacker must intercept the client-server communication on the network.

Affected Version(s)

SIMATIC RTLS Locating Manager 0

SIMATIC RTLS Locating Manager 0

SIMATIC RTLS Locating Manager 0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.