cbcvebase.
CVE-2025-40746
published 2025-08-12

CVE-2025-40746: A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a backup…

PriorityP350high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.63%
45.8th percentile
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a backup script. This could allow an authenticated remote attacker with high privileges in the application to execute arbitrary code with 'NT Authority/SYSTEM' privileges.

Affected

2 ranges
VendorProductVersion rangeFixed in
siemenssimatic_rtls_locating_manager< V3.2V3.2
siemenssimatic_rtls_locating_manager< 3.23.2

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability targets improper input validation in a backup script within SIMATIC RTLS Locating Manager. Monitor for unexpected process creation or command execution originating from the backup script component running as 'NT Authority/SYSTEM'.
  • Alert on any process spawned with 'NT Authority/SYSTEM' privileges that originates from the SIMATIC RTLS Locating Manager application context, particularly from backup-related functionality.
  • Monitor network traffic for authenticated remote connections to SIMATIC RTLS Locating Manager (all versions < V3.2) from unexpected or external sources, especially interactions with backup script endpoints.
  • ·Exploitation requires an authenticated attacker with high privileges in the application; unauthenticated or low-privilege access is insufficient to trigger the vulnerability.
  • ·All versions of SIMATIC RTLS Locating Manager prior to V3.2 are affected. Detection and mitigation efforts should prioritize identifying unpatched instances.
  • ·No known public exploitation has been reported at the time of advisory publication, but the CVSS v4 score of 9.4 indicates critical severity warranting urgent attention.

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.