9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Description
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a backup script. This could allow an authenticated remote attacker with high privileges in the application to execute arbitrary code with 'NT Authority/SYSTEM' privileges.
AI Analysis
A vulnerability in SIMATIC RTLS Locating Manager allows authenticated remote attackers with high privileges to execute arbitrary code with SYSTEM privileges due to improper input validation in a backup script.
Basic Information
ID
CVE-2025-40746
Source
siemens
Published
Aug 12, 2025 at 11:17
Affected Product
Vendor
Siemens
Product
SIMATIC RTLS Locating Manager
Affected Versions
Siemens SIMATIC RTLS Locating Manager 0
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
CRITICAL
Vendor
Siemens
Product
SIMATIC RTLS Locating Manager
Version
All versions < V3.2