CVE 6.3 MEDIUM

CVE-2025-40751_CVE-2025-40751

6.3 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Description

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.

Basic Information

ID CVE-2025-40751
Source siemens
Published Aug 12, 2025 at 11:17

Affected Product

Vendor Siemens
Product SIMATIC RTLS Locating Manager
Affected Versions Siemens SIMATIC RTLS Locating Manager 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.