CVE-2024-30207

CRITICAL

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC RTLS...

Affects 0 products across 2 vendors.

BCS8.17
CVSS 3.110.0
CVSS v410.0
EPSS0.8%
Percentile54th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-321: CWE-321
◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability has been identified in multiple versions of SIMATIC RTLS Locating Manager, which uses a hard-coded key for symmetric cryptography. This can lead to compromised confidentiality, integrity, and availability of the system if exploited by an unauthenticated remote attacker who intercepts the communication.

BSID: BS-2024-GLOBAL-208392-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-30207?
A critical vulnerability has been identified in multiple versions of SIMATIC RTLS Locating Manager, which uses a hard-coded key for symmetric cryptography. This can lead to compromised confidentiality, integrity, and availability of the system if exploited by an unauthenticated remote attacker who intercepts the communication.
What is the CVSS score for CVE-2024-30207?
CVE-2024-30207 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 0.8%.
Is CVE-2024-30207 actively exploited?
No confirmed active exploitation of CVE-2024-30207 as of 2026-05-30.
How do I remediate CVE-2024-30207?
Priority: IMMEDIATE.
What systems are affected by CVE-2024-30207?
CVE-2024-30207 affects: Fujitsu-Siemens, Siemens.
What NERC-CIP standard applies to CVE-2024-30207?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 because it involves the use of a hard-coded key, which does not meet the requirement for secure authentication and access control.
What IEC 62443 requirement maps to CVE-2024-30207?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves the use of a hard-coded key, which does not provide adequate protection against unauthorized access and data interception.
Vulnerability Details
CVE IDCVE-2024-30207
BSIDBS-2024-GLOBAL-208392-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2024-05-14
Last Modified2026-04-15
ICS Relevance65%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions < V3.0.1.1). The affected systems use symmetric cryptography with a hard-coded key to protect the communication between client and server. This could allow an unauthenticated remote attacker to compromise confidentiality and integrity of the communication and, subsequently, availability of the system. A successful exploit requires the attacker to gain knowledge of the hard-coded key and to be able to intercept the communication between client and server on the network.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability involves the use of a hard-coded key for symmetric cryptography in the communication between the client and server. An unauthenticated remote attacker who gains knowledge of the hard-coded key and can intercept the network traffic can exploit this vulnerability to compromise the confidentiality, integrity, and availability of the system.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Fujitsu-Siemens &mdash;
Siemens &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 802 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement network segmentation and encryption to prevent unauthorized access to the communication between the client and server. Use strong, unique keys for encryption and regularly rotate them.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 because it involves the use of a hard-coded key, which does not meet the requirement for secure authentication and access control.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves the use of a hard-coded key, which does not provide adequate protection against unauthorized access and data interception.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hasha1f9b11b709bcbd6901a85d9817dc8500e92e1d18f827531f976f424a5b4683fd39083880190f3dd8bb2498fa1e0e9e8731e412cd751ddb5f4acdefd3e0a95a6
Related CVEs affecting Fujitsu-Siemens
CVE-2024-44102 10.0 A vulnerability has been identified in PP TeleControl Server Basic 1000 to 50... CVE-2025-32433 10.0 Erlang/OTP is a set of libraries for the Erlang programming language. Prior t... CVE-2008-5810 10.0 WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, an... CVE-2024-32741 10.0 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).... CVE-2023-29131 10.0 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5)....
View all Fujitsu-Siemens CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →