PT-2020-11883 · Siemens · Simatic Rtls Locating Manager
Published
2020-09-09
·
Updated
2020-09-14
·
CVE-2020-10050
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SIMATIC RTLS Locating Manager versions prior to V2.10.2
Description
A local attacker could exploit a vulnerability to include arbitrary commands that are executed with SYSTEM privileges when the system restarts, due to the directory of service executables of the affected application being accessible.
Recommendations
For versions prior to V2.10.2, update to version V2.10.2 or later to resolve the issue.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Rtls Locating Manager