PT-2020-11882 · Siemens · Simatic Rtls Locating Manager
Published
2020-09-09
·
Updated
2020-09-14
·
CVE-2020-10049
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SIMATIC RTLS Locating Manager versions prior to V2.10.2
Description
A local attacker could exploit the vulnerability in the start-stop scripts for the services of the affected application to include arbitrary commands that are executed when services are started or stopped interactively by system administrators.
Recommendations
For versions prior to V2.10.2, update to version V2.10.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the start-stop scripts for the services to minimize the risk of exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Rtls Locating Manager