CVE-2025-40746
published 2025-08-12CVE-2025-40746: A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a backup…
PriorityP350high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.63%
45.8th percentile
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a backup script. This could allow an authenticated remote attacker with high privileges in the application to execute arbitrary code with 'NT Authority/SYSTEM' privileges.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_rtls_locating_manager | < V3.2 | V3.2 |
| siemens | simatic_rtls_locating_manager | < 3.2 | 3.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability targets improper input validation in a backup script within SIMATIC RTLS Locating Manager. Monitor for unexpected process creation or command execution originating from the backup script component running as 'NT Authority/SYSTEM'. ↗
- →Alert on any process spawned with 'NT Authority/SYSTEM' privileges that originates from the SIMATIC RTLS Locating Manager application context, particularly from backup-related functionality. ↗
- →Monitor network traffic for authenticated remote connections to SIMATIC RTLS Locating Manager (all versions < V3.2) from unexpected or external sources, especially interactions with backup script endpoints. ↗
- ·Exploitation requires an authenticated attacker with high privileges in the application; unauthenticated or low-privilege access is insufficient to trigger the vulnerability. ↗
- ·All versions of SIMATIC RTLS Locating Manager prior to V3.2 are affected. Detection and mitigation efforts should prioritize identifying unpatched instances. ↗
- ·No known public exploitation has been reported at the time of advisory publication, but the CVSS v4 score of 9.4 indicates critical severity warranting urgent attention. ↗
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5942-2jh9-wwqf: A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3
ghsa_unreviewed·2025-08-12
CVE-2025-40746 [CRITICAL] CWE-20 GHSA-5942-2jh9-wwqf: A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a backup script. This could allow an authenticated remote attacker with high privileges in the application to execute arbitrary code with 'NT Authority/SYSTEM' privileges.
CISA ICS
Siemens SIMATIC RTLS Locating Manager
cisa_ics·2025-08-14·CVSS 9.1
[CRITICAL] Siemens SIMATIC RTLS Locating Manager
ICS Advisory
##
Siemens SIMATIC RTLS Locating Manager
Release DateAugust 14, 2025
Alert CodeICSA-25-226-13
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC RTLS Locating Manager
- Vulnerability: Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-12
Published