PatchSiren cyber security CVE debrief
CVE-2025-32833 Siemens CVE debrief
CVE-2025-32833 is a high-severity SQL injection vulnerability in Siemens TeleControl Server Basic. According to the CISA CSAF advisory and Siemens security advisory, the flaw affects the internally used UnlockProjectUserRights method and can let an authenticated remote attacker bypass authorization controls, read and write the application database, and execute code as NT AUTHORITY\\NetworkService. The vendor and CISA both note that exploitation requires network access to port 8000 on a vulnerable system.
- Vendor
- Siemens
- Product
- TeleControl Server Basic
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-16
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-04-16
- Advisory updated
- 2025-05-06
Who should care
OT/ICS defenders, Siemens TeleControl Server Basic administrators, SOC teams monitoring externally reachable industrial services, and vulnerability management teams responsible for Windows-based server applications exposed on port 8000.
Technical summary
The advisory describes an SQL injection condition in TeleControl Server Basic’s UnlockProjectUserRights method. The impact includes authorization bypass, database read/write access, and remote code execution under the NetworkService account. The CVSS vector supplied in the source is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, reflecting that an attacker needs some authenticated access but no user interaction. CISA’s remediation guidance includes restricting port 8000 to trusted IPs and updating to V3.1.2.2 or later.
Defensive priority
High. This is internet-reachable only if port 8000 is exposed, but the impact is severe enough to prioritize rapid patching and access restriction wherever TeleControl Server Basic is deployed.
Recommended defensive actions
- Update Siemens TeleControl Server Basic to V3.1.2.2 or later.
- Restrict access to port 8000 on affected systems to trusted IP addresses only.
- Audit deployments to identify any TeleControl Server Basic instances reachable from untrusted networks.
- Review authentication and authorization logs for unusual use of the UnlockProjectUserRights-related workflow.
- Apply standard ICS defense-in-depth controls for segmented network access and least privilege.
Evidence notes
Primary facts come from the CISA CSAF advisory ICSA-25-112-01 and Siemens advisory SSA-443402, both referenced in the source corpus. The supplied source states the vulnerability is SQL injection in UnlockProjectUserRights, that exploitation requires an authenticated remote attacker with access to port 8000, and that the impact includes database access and execution as NT AUTHORITY\\NetworkService. The source revision history shows a 2025-05-06 revision for typo fixes only.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-32833 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-32833
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-32833 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-32833
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-112-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-443402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-443402.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-112-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.