PT-2021-9136 · Siemens · Simatic Rtls Locating Manager
Published
2021-11-09
·
Updated
2021-11-11
·
CVE-2020-10054
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SIMATIC RTLS Locating Manager versions prior to V2.12
Description
A issue has been identified where the application does not properly handle the import of large configuration files. This could allow a local attacker to import a specially crafted file, potentially leading to a denial-of-service condition of the application service.
Recommendations
For versions prior to V2.12, update to version V2.12 or later to resolve the issue. As a temporary workaround, consider restricting the import of large configuration files to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Rtls Locating Manager