#VU46518 Incorrect default permissions in SIMATIC RTLS Locating Manager - CVE-2020-10049
Published: September 9, 2020
SIMATIC RTLS Locating Manager
Siemens
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions for files and folders that are set by the application within the start-stop scripts. A local user can include arbitrary commands that are executed when services are started or stopped interactively by system administrators.