216.73.217.22

CVE-2025-40746

· Published 12/08/2025 12:15 · Modified 12/08/2025 14:25

Labels: CVE-2025-40746 2025-08-12CVE-2025-40746CWE-20[email protected]

Essential information

Published
12/08/2025 12:15
Modified
12/08/2025 14:25
Author
Creator
CVSS
9.4 CRITICAL (v3) 9.4 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a backup script. This could allow an authenticated remote attacker with high privileges in the application to execute arbitrary code with 'NT Authority/SYSTEM' privileges.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
siemens / simatic rtls locating manager cpe:2.3:a:siemens:simatic_rtls_locating_manager:<3.2:*:*:*:*:*:*:*

References