A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The directory of service executables of the affected application could allow a local attacker to include arbitrary commands that are executed with SYSTEM privileges when the system restarts.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-251935.pdf | vendor advisory |