CVE-2025-30034: Medium severity Siemens SIMATIC RTLS Locating Manager vulnerability
Published Aug 12, 2025
·Updated
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected devices do not properly validate input sent to its listening port on the local loopback interface. This could allow an unauthenticated local attacker to cause a denial of service condition.
Affected Software
2 affected components
Siemens SIMATIC RTLS Locating Manager<3.3
Siemens SIMATIC RTLS Locating Manager<3.3
Event History
Aug 12, 2025
CVE Published
via MITRE·11:16 AM
Data Sourced
via MITRE·11:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-30034?
CVE-2025-30034 is classified as a denial of service vulnerability.
2
How do I fix CVE-2025-30034?
To mitigate CVE-2025-30034, upgrade to SIMATIC RTLS Locating Manager version 3.3 or higher.
3
Who is affected by CVE-2025-30034?
CVE-2025-30034 affects all versions of the SIMATIC RTLS Locating Manager prior to version 3.3.
4
What can an attacker do with CVE-2025-30034?
An attacker can cause a denial of service condition on affected devices by sending specially crafted input.
5
Is authentication required to exploit CVE-2025-30034?
No, CVE-2025-30034 can be exploited by an unauthenticated local attacker.