Hard-coded Key Vulnerability in SIMATIC RTLS Locating Manager Could Lead to Confidentiality and Integrity Breaches
CVE-2024-30207
What is CVE-2024-30207?
A vulnerability has been identified in the SIMATIC RTLS Locating Manager products from Siemens. This issue affects several versions prior to V3.0.1.1. The vulnerability arises from the use of symmetric cryptography that relies on a hard-coded key, which is employed to secure communication between client and server. Attackers with knowledge of this key can potentially intercept communications, leading to a compromise of confidentiality and integrity, ultimately affecting system availability. To exploit this vulnerability, an attacker must intercept the client-server communication on the network.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SIMATIC RTLS Locating Manager 0
SIMATIC RTLS Locating Manager 0
SIMATIC RTLS Locating Manager 0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved