Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5942-2jh9-wwqf

Опубликовано: 12 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.4
CVSS3: 9.1

Описание

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a backup script. This could allow an authenticated remote attacker with high privileges in the application to execute arbitrary code with 'NT Authority/SYSTEM' privileges.

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a backup script. This could allow an authenticated remote attacker with high privileges in the application to execute arbitrary code with 'NT Authority/SYSTEM' privileges.

EPSS

Процентиль: 53%
0.00297
Низкий

9.4 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.1
nvd
6 месяцев назад

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a backup script. This could allow an authenticated remote attacker with high privileges in the application to execute arbitrary code with 'NT Authority/SYSTEM' privileges.

CVSS3: 9.1
fstec
6 месяцев назад

Уязвимость программного обеспечения для расчета позиций отдельных RTLS-транспондеров SIMATIC RTLS Locating Manager, связанная с недостатками механизма проверки входных данных при выполнении сценариев резервного копирования, позволяющая нарушителю выполнить произвольный код с правами SYSTEM

EPSS

Процентиль: 53%
0.00297
Низкий

9.4 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-20