PatchSiren cyber security CVE debrief
CVE-2025-32854 Siemens CVE debrief
CVE-2025-32854 affects Siemens TeleControl Server Basic and was published on 2025-04-16. CISA and Siemens describe an SQL injection in the internally used LockOpcSettings method. If an authenticated remote attacker can reach port 8000 on a vulnerable system, they may bypass authorization controls, read and write the application's database, and execute code with NT AUTHORITY\NetworkService permissions. Siemens recommends updating to V3.1.2.2 or later and limiting access to port 8000 to trusted IP addresses only.
- Vendor
- Siemens
- Product
- TeleControl Server Basic
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-16
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-04-16
- Advisory updated
- 2025-05-06
Who should care
Operators and administrators running Siemens TeleControl Server Basic, especially systems exposed on port 8000 or reachable by authenticated remote users. OT/ICS teams, Windows service administrators, and defenders responsible for segmentation and patching should prioritize review.
Technical summary
The advisory describes a network-reachable SQL injection affecting the internally used LockOpcSettings method in Siemens TeleControl Server Basic. The attack requires authenticated access and connectivity to port 8000 on the vulnerable host. Successful exploitation can bypass authorization, manipulate application database content, and execute code as NT AUTHORITY\NetworkService. The vendor remediation is to update to V3.1.2.2 or later; the immediate mitigation is to restrict port 8000 to trusted IP addresses only.
Defensive priority
High. The issue is network reachable, requires authentication but can lead to authorization bypass, database compromise, and code execution, and it is scored CVSS 8.8 (HIGH).
Recommended defensive actions
- Update Siemens TeleControl Server Basic to V3.1.2.2 or later.
- Restrict access to port 8000 on affected systems to trusted IP addresses only.
- Confirm whether any deployments expose port 8000 beyond required OT or management boundaries.
- Apply ICS defense-in-depth and segmentation practices for systems that must remain online.
Evidence notes
All vulnerability details and mitigations are taken from the CISA CSAF advisory ICSA-25-112-01 and the Siemens advisory references included in the source corpus. The source advisory was published on 2025-04-16 and revised on 2025-05-06 for typo fixes. No exploit-in-the-wild, ransomware, or additional product-version details are asserted beyond the supplied material.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-32854 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-32854
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-32854 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-32854
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-112-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-443402.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-443402.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-112-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.