Input Validation Flaw in SIMATIC RTLS Locating Manager by Siemens
CVE-2025-40746
9.4CRITICAL
What is CVE-2025-40746?
A serious input validation flaw exists in the SIMATIC RTLS Locating Manager, impacting all versions prior to V3.2. This vulnerability allows an authenticated remote attacker with high privileges to exploit the backup script, potentially executing arbitrary code with 'NT Authority/SYSTEM' privileges. Effective mitigation measures should be taken to protect against unauthorized access and to ensure system integrity.
Affected Version(s)
SIMATIC RTLS Locating Manager 0
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved