CVE-2024-30207
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC RTLS...
Affects 0 products across 2 vendors.
A critical vulnerability has been identified in multiple versions of SIMATIC RTLS Locating Manager, which uses a hard-coded key for symmetric cryptography. This can lead to compromised confidentiality, integrity, and availability of the system if exploited by an unauthenticated remote attacker who intercepts the communication.
BSID: BS-2024-GLOBAL-208392-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2024-30207?
What is the CVSS score for CVE-2024-30207?
Is CVE-2024-30207 actively exploited?
How do I remediate CVE-2024-30207?
What systems are affected by CVE-2024-30207?
What NERC-CIP standard applies to CVE-2024-30207?
What IEC 62443 requirement maps to CVE-2024-30207?
| CVE ID | CVE-2024-30207 |
|---|---|
| BSID | BS-2024-GLOBAL-208392-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2024-05-14 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 65% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions < V3.0.1.1). The affected systems use symmetric cryptography with a hard-coded key to protect the communication between client and server. This could allow an unauthenticated remote attacker to compromise confidentiality and integrity of the communication and, subsequently, availability of the system. A successful exploit requires the attacker to gain knowledge of the hard-coded key and to be able to intercept the communication between client and server on the network.
Source: NIST NVD / MITRE CVE Database
The vulnerability involves the use of a hard-coded key for symmetric cryptography in the communication between the client and server. An unauthenticated remote attacker who gains knowledge of the hard-coded key and can intercept the network traffic can exploit this vulnerability to compromise the confidentiality, integrity, and availability of the system.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Fujitsu-Siemens | — | — |
| Siemens | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement network segmentation and encryption to prevent unauthorized access to the communication between the client and server. Use strong, unique keys for encryption and regularly rotate them.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 because it involves the use of a hard-coded key, which does not meet the requirement for secure authentication and access control.
This CVE maps to SR 7.6 because it involves the use of a hard-coded key, which does not provide adequate protection against unauthorized access and data interception.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | a1f9b11b709bcbd6901a85d9817dc8500e92e1d18f827531f976f424a5b4683fd39083880190f3dd8bb2498fa1e0e9e8731e412cd751ddb5f4acdefd3e0a95a6 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →