PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-33583 Siemens CVE debrief

A hidden debug configuration item in Siemens SIMATIC RTLS Locating Manager could allow authenticated local attackers to gain insight into internal deployment configuration. The vulnerability was published on May 14, 2024, and modified on June 11, 2024. Siemens has released version V3.0.1.1 or later to address this issue.

Vendor
Siemens
Product
SIMATIC RTLS Locating Manager (6GT2780-0DA00)
CVSS
LOW 3.3
CISA KEV
Not listed in stored evidence
Original CVE published
2024-05-14
Original CVE updated
2024-06-11
Advisory published
2024-05-14
Advisory updated
2024-06-11

Who should care

Organizations operating Siemens SIMATIC RTLS Locating Manager in industrial environments, particularly those with multi-user access to RTLS infrastructure or shared Windows Server deployments. Security teams responsible for OT/ICS asset management and hardening should prioritize this low-severity update within standard patch cycles.

Technical summary

The affected application contains a hidden configuration item that enables debug functionality. An authenticated local attacker with access to the system could leverage this to gain insight into the internal configuration of the deployment. The CVSS v3.1 vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C indicates a local attack vector with low attack complexity, requiring low privileges and no user interaction, resulting in low confidentiality impact with no integrity or availability impact. The vulnerability affects seven product variants of SIMATIC RTLS Locating Manager (6GT2780-0DA00, 6GT2780-0DA10, 6GT2780-0DA20, 6GT2780-0DA30, 6GT2780-1EA10, 6GT2780-1EA20, 6GT2780-1EA30).

Defensive priority

low

Recommended defensive actions

  • Update SIMATIC RTLS Locating Manager to V3.0.1.1 or later version available through Siemens Online Software Delivery (OSD)
  • Install required RTLS Locating Manager components on a single host computer where possible and ensure only trusted persons have access to the system
  • Secure the Windows Server hosting RTLS Locating Manager with a firewall and ensure no ports are accessible from untrusted networks
  • Apply security hardening of the Windows Server hosting RTLS Locating Manager in accordance with corporate security policies or up-to-date hardening guidelines

Evidence notes

Evidence drawn from CISA CSAF advisory ICSA-24-137-07 and Siemens product security advisory SSA-093430. CVSS 3.3 (LOW) reflects local attack vector with low confidentiality impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-33583 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-33583

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-33583 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-33583

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-137-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-093430.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-093430.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/pdf/ssa-093430.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/txt/ssa-093430.txt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-137-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.