Potential Privilege Escalation Vulnerability in SIMATIC RTLS Locating Manager
CVE-2024-33499
9.1CRITICAL
What is CVE-2024-33499?
A vulnerability exists within the SIMATIC RTLS Locating Manager software developed by Siemens, impacting several versions prior to V3.0.1.1. The flaw stems from improper management of user permissions in a critical user management component. This misconfiguration could potentially allow an attacker who has already obtained administrative access to elevate their privileges to the Systemadministrator level, granting them broader control over the system. Organizations using the affected products are advised to apply the recommended updates to mitigate this vulnerability and enhance their security posture.
Affected Version(s)
SIMATIC RTLS Locating Manager 0
SIMATIC RTLS Locating Manager 0
SIMATIC RTLS Locating Manager 0