A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The start-stop scripts for the services of the affected application could allow a local attacker to include arbitrary commands that are executed when services are started or stopped interactively by system administrators.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-251935.pdf | vendor advisory |