PatchSiren cyber security CVE debrief
CVE-2024-33583 Siemens CVE debrief
A hidden debug configuration item in Siemens SIMATIC RTLS Locating Manager could allow authenticated local attackers to gain insight into internal deployment configuration. The vulnerability was published on May 14, 2024, and modified on June 11, 2024. Siemens has released version V3.0.1.1 or later to address this issue.
- Vendor
- Siemens
- Product
- SIMATIC RTLS Locating Manager (6GT2780-0DA00)
- CVSS
- LOW 3.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-05-14
- Original CVE updated
- 2024-06-11
- Advisory published
- 2024-05-14
- Advisory updated
- 2024-06-11
Who should care
Organizations operating Siemens SIMATIC RTLS Locating Manager in industrial environments, particularly those with multi-user access to RTLS infrastructure or shared Windows Server deployments. Security teams responsible for OT/ICS asset management and hardening should prioritize this low-severity update within standard patch cycles.
Technical summary
The affected application contains a hidden configuration item that enables debug functionality. An authenticated local attacker with access to the system could leverage this to gain insight into the internal configuration of the deployment. The CVSS v3.1 vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C indicates a local attack vector with low attack complexity, requiring low privileges and no user interaction, resulting in low confidentiality impact with no integrity or availability impact. The vulnerability affects seven product variants of SIMATIC RTLS Locating Manager (6GT2780-0DA00, 6GT2780-0DA10, 6GT2780-0DA20, 6GT2780-0DA30, 6GT2780-1EA10, 6GT2780-1EA20, 6GT2780-1EA30).
Defensive priority
low
Recommended defensive actions
- Update SIMATIC RTLS Locating Manager to V3.0.1.1 or later version available through Siemens Online Software Delivery (OSD)
- Install required RTLS Locating Manager components on a single host computer where possible and ensure only trusted persons have access to the system
- Secure the Windows Server hosting RTLS Locating Manager with a firewall and ensure no ports are accessible from untrusted networks
- Apply security hardening of the Windows Server hosting RTLS Locating Manager in accordance with corporate security policies or up-to-date hardening guidelines
Evidence notes
Evidence drawn from CISA CSAF advisory ICSA-24-137-07 and Siemens product security advisory SSA-093430. CVSS 3.3 (LOW) reflects local attack vector with low confidentiality impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-33583 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-33583
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-33583 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-33583
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-137-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-093430.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-093430.html
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/pdf/ssa-093430.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/txt/ssa-093430.txt
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-137-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.