PT-2021-9136 · Siemens · Simatic Rtls Locating Manager

Published

2021-11-09

·

Updated

2021-11-11

·

CVE-2020-10054

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SIMATIC RTLS Locating Manager versions prior to V2.12
Description A issue has been identified where the application does not properly handle the import of large configuration files. This could allow a local attacker to import a specially crafted file, potentially leading to a denial-of-service condition of the application service.
Recommendations For versions prior to V2.12, update to version V2.12 or later to resolve the issue. As a temporary workaround, consider restricting the import of large configuration files to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10054

Affected Products

Simatic Rtls Locating Manager