Credential Management Flaw in SIMATIC RTLS Locating Manager by Siemens
CVE-2025-40751

4.8MEDIUM

Key Information:

Vendor

Siemens

Vendor
CVE Published:
12 August 2025

What is CVE-2025-40751?

A significant security issue has been discovered in the SIMATIC RTLS Locating Manager prior to version 3.3, where the Report Clients inadequately safeguard authentication credentials. This vulnerability allows an authenticated local attacker to access and potentially misuse these credentials, facilitating unauthorized elevation of privileges from a standard Manager role to a Systemadministrator role, hence compromising the integrity and security of the entire system.

Affected Version(s)

SIMATIC RTLS Locating Manager 0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-40751 : Credential Management Flaw in SIMATIC RTLS Locating Manager by Siemens