PatchSiren cyber security CVE debrief
CVE-2025-30002 Siemens CVE debrief
CVE-2025-30002 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the CISA CSAF advisory, the flaw is in the internally used UpdateConnectionVariables method and can let an authenticated remote attacker bypass authorization controls, read from and write to the application's database, and execute code as NT AUTHORITY\NetworkService. Successful exploitation requires network access to port 8000 on a vulnerable system. Siemens and CISA list an update to V3.1.2.2 or later and access restriction on port 8000 as the primary defensive steps.
- Vendor
- Siemens
- Product
- TeleControl Server Basic
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-16
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-04-16
- Advisory updated
- 2025-05-06
Who should care
Organizations running Siemens TeleControl Server Basic, especially OT/ICS operators, system owners, and defenders responsible for network segmentation, host hardening, and patch management on systems exposing port 8000.
Technical summary
The advisory describes a SQL injection condition in the internally used UpdateConnectionVariables method. The attack requires an authenticated remote attacker with reachability to port 8000 on a vulnerable instance. Impact includes authorization bypass, database read/write access, and code execution under the NT AUTHORITY\NetworkService account. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, reflecting network reachability, low attack complexity, and high confidentiality, integrity, and availability impact.
Defensive priority
High. The issue is remotely reachable, requires authentication but no user interaction, and can lead to full application-level compromise with code execution in an OT product. Prioritize patching and exposure reduction promptly, especially where port 8000 is reachable beyond tightly controlled internal segments.
Recommended defensive actions
- Update Siemens TeleControl Server Basic to V3.1.2.2 or later.
- Restrict access to port 8000 on affected systems to trusted IP addresses only.
- Verify whether any affected instances are exposed beyond the intended management network.
- Apply OT network segmentation and least-privilege access controls consistent with CISA ICS recommended practices.
- Review logs for unusual authentication attempts, database activity, or unexpected service behavior on affected hosts.
Evidence notes
The source corpus identifies Siemens TeleControl Server Basic as the affected product, with CISA CSAF advisory ICSA-25-112-01 published on 2025-04-16 and revised on 2025-05-06 for typo fixes. The advisory text explicitly states the SQL injection path, the need for authenticated remote access, the port 8000 requirement, and the potential for code execution as NT AUTHORITY\NetworkService. The supplied enrichment marks this as not KEV-listed.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-30002 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-30002
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-30002 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-30002
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-112-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-443402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-443402.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-112-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.