PatchSiren cyber security CVE debrief
CVE-2025-40765 Siemens CVE debrief
CVE-2025-40765 is a critical information disclosure vulnerability in Siemens TeleControl Server Basic V3.1. According to the CISA CSAF advisory and the Siemens product security advisory, an unauthenticated remote attacker could obtain user password hashes and then use them to log in and perform authenticated operations of the database service. Because the issue is network-reachable, requires no user interaction, and is assigned CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), it should be treated as an urgent remediation item for affected deployments.
- Vendor
- Siemens
- Product
- TeleControl Server Basic V3.1
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-10-14
- Original CVE updated
- 2025-10-14
- Advisory published
- 2025-10-14
- Advisory updated
- 2025-10-14
Who should care
OT and ICS operators running Siemens TeleControl Server Basic V3.1, system owners responsible for the database service, and security teams that manage exposed industrial services or remote access to port 8000.
Technical summary
The advisory describes an information disclosure condition in Siemens TeleControl Server Basic V3.1 that can be abused by an unauthenticated remote attacker. The stated impact is disclosure of password hashes, followed by the possibility of logging in and carrying out authenticated operations against the database service. The provided CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, which aligns with a high-severity, remotely reachable issue affecting confidentiality, integrity, and availability.
Defensive priority
Immediate. This is a critical, unauthenticated, network-accessible issue with vendor-provided remediation available.
Recommended defensive actions
- Update affected systems to Siemens TeleControl Server Basic V3.1.2.3 or later.
- Restrict access to port 8000 on affected systems to trusted IP addresses only, as directed in the advisory.
- Review exposure of any affected database-service interfaces and limit network reachability to the minimum necessary.
- If the product is internet-facing or reachable from broader OT/IT networks, prioritize emergency change management and validate the update path before rollout.
- Monitor for unexpected authentication events or database-service activity until remediation is complete.
Evidence notes
The supplied CISA CSAF source item for ICSA-25-289-09 states: "The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated operations of the database service." The same source lists Siemens TeleControl Server Basic V3.1 as the affected product and recommends restricting access to port 8000 to trusted IP addresses only, plus updating to V3.1.2.3 or later. The source references the Siemens advisory (ssa-062309) and the CISA advisory page for corroboration.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-40765 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-40765
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-40765 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40765
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-289-09.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-062309.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-062309.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-289-09
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.