PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-32855 Siemens CVE debrief

CVE-2025-32855 affects Siemens TeleControl Server Basic. The supplied CISA/Siemens advisory says the internally used UnlockOpcSettings method is vulnerable to SQL injection. An authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, and execute code with NT AUTHORITY\NetworkService permissions. Siemens' remediation is to update to V3.1.2.2 or later; until then, restrict port 8000 to trusted IP addresses only.

Vendor
Siemens
Product
TeleControl Server Basic
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-04-16
Original CVE updated
2025-05-06
Advisory published
2025-04-16
Advisory updated
2025-05-06

Who should care

Operators and administrators of Siemens TeleControl Server Basic, OT/ICS security teams, and network defenders responsible for systems exposing port 8000.

Technical summary

The advisory describes a network-reachable SQL injection in the UnlockOpcSettings method of Siemens TeleControl Server Basic. The attack requires authenticated access and connectivity to port 8000, and the reported impact includes authorization bypass, database read/write access, and code execution in the NT AUTHORITY\NetworkService context. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, which aligns with the high-severity assessment.

Defensive priority

High. The issue combines authenticated remote reachability, database compromise potential, and code execution in a service account context, so exposed instances should be prioritized for patching and exposure reduction.

Recommended defensive actions

  • Update Siemens TeleControl Server Basic to V3.1.2.2 or later.
  • Restrict access to port 8000 on affected systems to trusted IP addresses only.
  • Inventory all TeleControl Server Basic deployments and identify any exposed or cross-zone-reachable instances.
  • Review OT network segmentation and authentication controls around the service.
  • Monitor for unusual database activity or service behavior until remediation is complete.

Evidence notes

This debrief is based on the supplied CISA CSAF advisory ICSA-25-112-01 and its Siemens references. The advisory was published on 2025-04-16 and revised on 2025-05-06; the revision history in the supplied corpus says the update fixed typos only. The source description explicitly names the vulnerable method (UnlockOpcSettings), the access prerequisite (port 8000), and the vendor fix (V3.1.2.2 or later). The enrichment provided with the request marks the issue as not in CISA KEV.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-32855 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-32855

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-32855 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-32855

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-112-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-443402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-443402.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-112-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.