A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). Multiple services of the affected application are executed with SYSTEM privileges while the call path is not quoted. This could allow a local attacker to inject arbitrary commands that are execeuted instead of the legitimate service.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2020-09-09T18:09:58
Updated: 2024-08-04T10:50:57.830Z
Reserved: 2020-03-04T00:00:00
Link: CVE-2020-10051
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2020-09-09T19:15:18.587
Modified: 2020-09-14T19:09:47.863
Link: CVE-2020-10051
Redhat
No data.