Siemens SIMATIC RTLS Locating Manager
cpe:2.3:a:siemens:simatic_rtls_locating_manager:*:*:*:*:*:*:*
- < 3.3
A vulnerability exists in Siemens SIMATIC RTLS Locating Manager Report Clients, all versions prior to 3.3. These clients fail to adequately protect credentials used for server authentication, potentially allowing an authenticated local attacker to intercept these credentials and escalate access rights from the Manager role to the Systemadministrator role.
Exploitation of this vulnerability could lead to unauthorized access escalation, allowing a user to gain Systemadministrator privileges.
Users are advised to update to version 3.3 or later. Additional guidance can be found on the Siemens support portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.