PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-32858 Siemens CVE debrief

CVE-2025-32858 affects Siemens TeleControl Server Basic and was publicly disclosed on 2025-04-16. The advisory describes an SQL injection issue in the internally used UpdateWebServerGatewaySettings method. An authenticated remote attacker with access to port 8000 on a vulnerable system could bypass authorization controls, read and write the application's database, and execute code with NT AUTHORITY\NetworkService permissions. Siemens' remediation is to update to V3.1.2.2 or later; CISA also recommends restricting exposure of port 8000 to trusted IP addresses.

Vendor
Siemens
Product
TeleControl Server Basic
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-04-16
Original CVE updated
2025-05-06
Advisory published
2025-04-16
Advisory updated
2025-05-06

Who should care

Organizations running Siemens TeleControl Server Basic, especially OT/ICS operators exposing port 8000, as well as security teams responsible for perimeter filtering, asset inventory, and patching of Siemens-managed systems.

Technical summary

The supplied advisory identifies an SQL injection flaw in the internally used UpdateWebServerGatewaySettings method. The attack path requires authentication and network access to port 8000 on a vulnerable host. If exploited, the attacker may bypass authorization checks, interact with the database for read/write operations, and achieve code execution under the NetworkService account. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, matching a high-severity remote attack with low complexity and limited privileges.

Defensive priority

High. Treat as urgent for any exposed or reachable TeleControl Server Basic instance, because the flaw combines network reachability, authenticated access, database compromise, and potential code execution.

Recommended defensive actions

  • Update Siemens TeleControl Server Basic to V3.1.2.2 or later per vendor guidance.
  • Restrict access to port 8000 on affected systems to trusted IP addresses only.
  • Verify whether any instances are reachable from untrusted networks and remove unnecessary exposure.
  • Review authentication, application, and database logs for unexpected access or changes tied to the affected service.

Evidence notes

This debrief is based on the CISA CSAF advisory ICSA-25-112-01 for CVE-2025-32858, which cites Siemens TeleControl Server Basic and describes the SQL injection condition, required port 8000 access, and potential impacts. The supplied source also lists Siemens remediation to update to V3.1.2.2 or later and a mitigation to restrict port 8000 to trusted IP addresses. The advisory revision history shows an initial publication on 2025-04-16 and a typo-fixing revision on 2025-05-06.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-32858 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-32858

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-32858 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-32858

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-112-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-443402.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-443402.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-112-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.