Credential Management Flaw in SIMATIC RTLS Locating Manager by Siemens
CVE-2025-40751
4.8MEDIUM
What is CVE-2025-40751?
A significant security issue has been discovered in the SIMATIC RTLS Locating Manager prior to version 3.3, where the Report Clients inadequately safeguard authentication credentials. This vulnerability allows an authenticated local attacker to access and potentially misuse these credentials, facilitating unauthorized elevation of privileges from a standard Manager role to a Systemadministrator role, hence compromising the integrity and security of the entire system.
Affected Version(s)
SIMATIC RTLS Locating Manager 0