PT-2024-4510 · Siemens · Simatic Rtls Locating Manager
Published
2024-05-14
·
Updated
2024-06-11
·
CVE-2024-33498
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
SIMATIC RTLS Locating Manager versions prior to V3.0.1.1
Description
The issue is related to an uncontrolled resource consumption in the software, which can be exploited by a remote attacker to cause a denial of service condition. This happens when the software fails to properly release memory allocated for handling specially crafted incoming packets, leading to a crash of the service due to memory exhaustion. The service automatically restarts after a short time.
Recommendations
For SIMATIC RTLS Locating Manager versions prior to V3.0.1.1, update to version V3.0.1.1 or later to resolve the issue.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Rtls Locating Manager