Arbitrary Code Execution Vulnerability in SIMATIC RTLS Locating Manager Before V3.2
Act Now9.1SSA-493787Aug 12, 2025
Attack VectorNetwork
Auth RequiredHigh
ComplexityLow
User InteractionNone needed
Summary
SIMATIC RTLS Locating Manager Before V3.2 contains an improper input validation vulnerability that could allow an authenticated remote attacker to execute arbitrary code with high privileges.
What this means
What could happen
An attacker with valid credentials could run arbitrary code on the RTLS locating system with elevated privileges, potentially disrupting real-time location tracking of equipment and personnel in your facility.
Who's at risk
Facility managers and engineers using SIMATIC RTLS (Real-Time Locating System) for tracking equipment and personnel in manufacturing plants, warehouses, and large industrial facilities. This affects any organization relying on Siemens' location tracking infrastructure for operational awareness or safety compliance.
How it could be exploited
An attacker with valid engineering or administrative credentials sends specially crafted input to the Locating Manager over the network. The manager fails to properly validate the input and executes arbitrary code with high privileges, allowing the attacker to compromise the system and control location tracking operations.
Prerequisites
- Valid authentication credentials (engineering or administrative account)
- Network access to SIMATIC RTLS Locating Manager service
- RTLS Locating Manager version prior to 3.2
remotely exploitablerequires valid authenticationlow complexityhigh privilege escalationaffects location tracking operations
Exploitability
Low exploit probability (EPSS 0.5%)
Affected products (1)
ProductAffected VersionsFix Status
SIMATIC RTLS Locating Manager< 3.23.2
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate SIMATIC RTLS Locating Manager to version 3.2 or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/802e9936-89f6-453f-a4b3-3e9549780505