SIMATIC RTLS Locating Manager Credentials Leak < V3.0.1.1
CVE-2024-33496 Published on May 14, 2024

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions < V3.0.1.1). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.

NVD

Weakness Type

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.


Products Associated with CVE-2024-33496

Want to know whenever a new CVE is published for Siemens Simatic Rtls Locating Manager? stack.watch will email you.

 

Affected Versions

Siemens SIMATIC RTLS Locating Manager: Siemens SIMATIC RTLS Locating Manager: Siemens SIMATIC RTLS Locating Manager: Siemens SIMATIC RTLS Locating Manager: Siemens SIMATIC RTLS Locating Manager: Siemens SIMATIC RTLS Locating Manager: Siemens SIMATIC RTLS Locating Manager: siemens simatic_rtls_locating_manager:

Exploit Probability

EPSS
0.08%
Percentile
23.60%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.