HomeSiemensCVE-2025-40751

CVE-2025-40751

MEDIUM
4.8CVSS
Published: 2025-08-12
Updated: 2025-08-20
AI Analysis

Description

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.

CVSS Metrics

Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector
local
Complexity
low
Privileges
low
User Action
none
Confidentiality
undefined
Integrity
undefined
Availability
undefined
Weaknesses
CWE-522

Metadata

Primary Vendor
SIEMENS
Published
8/12/2025
Last Modified
8/20/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

siemens : simatic_rtls_locating_manager

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-40751 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com