CVE-2024-30207: Critical severity Siemens SIMATIC RTLS Locating Manager (6GT2780-0DA00) vulnerability

Published May 14, 2024
·
Updated

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions < V3.0.1.1). The affected systems use symmetric cryptography with a hard-coded key to protect the communication between client and server. This could allow an unauthenticated remote attacker to compromise confidentiality and integrity of the communication and, subsequently, availability of the system. A successful exploit requires the attacker to gain knowledge of the hard-coded key and to be able to intercept the communication between client and server on the network.

Affected Software

7 affected components
Siemens SIMATIC RTLS Locating Manager (6GT2780-0DA00)<V3.0.1.1
Siemens SIMATIC RTLS Locating Manager (6GT2780-0DA10)<V3.0.1.1
Siemens SIMATIC RTLS Locating Manager (6GT2780-0DA20)<V3.0.1.1
Siemens SIMATIC RTLS Locating Manager (6GT2780-0DA30)<V3.0.1.1
Siemens SIMATIC RTLS Locating Manager (6GT2780-1EA10)<V3.0.1.1
Siemens SIMATIC RTLS Locating Manager (6GT2780-1EA20)<V3.0.1.1
Siemens SIMATIC RTLS Locating Manager (6GT2780-1EA30)<V3.0.1.1

Event History

May 14, 2024
CVE Published
via MITRE·10:02 AM
Data Sourced
via MITRE·10:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2024-30207?

The severity of CVE-2024-30207 is critical due to the potential for unauthorized access to sensitive information.

2

How do I fix CVE-2024-30207?

To fix CVE-2024-30207, update the SIMATIC RTLS Locating Manager to version 3.0.1.1 or later.

3

Which versions of SIMATIC RTLS Locating Manager are affected by CVE-2024-30207?

All versions of SIMATIC RTLS Locating Manager prior to version 3.0.1.1 are affected by CVE-2024-30207.

4

What products are impacted by CVE-2024-30207?

Products impacted by CVE-2024-30207 include SIMATIC RTLS Locating Manager models 6GT2780-0DA00, 6GT2780-0DA10, 6GT2780-0DA20, 6GT2780-0DA30, 6GT2780-1EA10, 6GT2780-1EA20, and 6GT2780-1EA30.

5

Is there a workaround for CVE-2024-30207?

There are no reliable workarounds available for CVE-2024-30207; upgrading to the latest version is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203