PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-32833 Siemens CVE debrief

CVE-2025-32833 is a high-severity SQL injection vulnerability in Siemens TeleControl Server Basic. According to the CISA CSAF advisory and Siemens security advisory, the flaw affects the internally used UnlockProjectUserRights method and can let an authenticated remote attacker bypass authorization controls, read and write the application database, and execute code as NT AUTHORITY\\NetworkService. The vendor and CISA both note that exploitation requires network access to port 8000 on a vulnerable system.

Vendor
Siemens
Product
TeleControl Server Basic
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-04-16
Original CVE updated
2025-05-06
Advisory published
2025-04-16
Advisory updated
2025-05-06

Who should care

OT/ICS defenders, Siemens TeleControl Server Basic administrators, SOC teams monitoring externally reachable industrial services, and vulnerability management teams responsible for Windows-based server applications exposed on port 8000.

Technical summary

The advisory describes an SQL injection condition in TeleControl Server Basic’s UnlockProjectUserRights method. The impact includes authorization bypass, database read/write access, and remote code execution under the NetworkService account. The CVSS vector supplied in the source is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, reflecting that an attacker needs some authenticated access but no user interaction. CISA’s remediation guidance includes restricting port 8000 to trusted IPs and updating to V3.1.2.2 or later.

Defensive priority

High. This is internet-reachable only if port 8000 is exposed, but the impact is severe enough to prioritize rapid patching and access restriction wherever TeleControl Server Basic is deployed.

Recommended defensive actions

  • Update Siemens TeleControl Server Basic to V3.1.2.2 or later.
  • Restrict access to port 8000 on affected systems to trusted IP addresses only.
  • Audit deployments to identify any TeleControl Server Basic instances reachable from untrusted networks.
  • Review authentication and authorization logs for unusual use of the UnlockProjectUserRights-related workflow.
  • Apply standard ICS defense-in-depth controls for segmented network access and least privilege.

Evidence notes

Primary facts come from the CISA CSAF advisory ICSA-25-112-01 and Siemens advisory SSA-443402, both referenced in the source corpus. The supplied source states the vulnerability is SQL injection in UnlockProjectUserRights, that exploitation requires an authenticated remote attacker with access to port 8000, and that the impact includes database access and execution as NT AUTHORITY\\NetworkService. The source revision history shows a 2025-05-06 revision for typo fixes only.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-32833 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-32833

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-32833 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-32833

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-112-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-443402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-443402.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-112-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.