Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pm6-hr95-ggxq

Опубликовано: 12 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 6.3

Описание

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.

EPSS

Процентиль: 3%
0.00015
Низкий

4.8 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6.3
nvd
6 месяцев назад

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.

CVSS3: 6.3
fstec
6 месяцев назад

Уязвимость программного обеспечения для расчета позиций отдельных RTLS-транспондеров SIMATIC RTLS Locating Manager, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 3%
0.00015
Низкий

4.8 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-522