Potential Privilege Escalation Vulnerability in SIMATIC RTLS Locating Manager
CVE-2024-33499

9.1CRITICAL

Key Information:

Vendor
Siemens
Vendor
CVE Published:
14 May 2024

Summary

A vulnerability exists within the SIMATIC RTLS Locating Manager software developed by Siemens, impacting several versions prior to V3.0.1.1. The flaw stems from improper management of user permissions in a critical user management component. This misconfiguration could potentially allow an attacker who has already obtained administrative access to elevate their privileges to the Systemadministrator level, granting them broader control over the system. Organizations using the affected products are advised to apply the recommended updates to mitigate this vulnerability and enhance their security posture.

Affected Version(s)

SIMATIC RTLS Locating Manager 0

SIMATIC RTLS Locating Manager 0

SIMATIC RTLS Locating Manager 0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.