PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-40765 Siemens CVE debrief

CVE-2025-40765 is a critical information disclosure vulnerability in Siemens TeleControl Server Basic V3.1. According to the CISA CSAF advisory and the Siemens product security advisory, an unauthenticated remote attacker could obtain user password hashes and then use them to log in and perform authenticated operations of the database service. Because the issue is network-reachable, requires no user interaction, and is assigned CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), it should be treated as an urgent remediation item for affected deployments.

Vendor
Siemens
Product
TeleControl Server Basic V3.1
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-10-14
Original CVE updated
2025-10-14
Advisory published
2025-10-14
Advisory updated
2025-10-14

Who should care

OT and ICS operators running Siemens TeleControl Server Basic V3.1, system owners responsible for the database service, and security teams that manage exposed industrial services or remote access to port 8000.

Technical summary

The advisory describes an information disclosure condition in Siemens TeleControl Server Basic V3.1 that can be abused by an unauthenticated remote attacker. The stated impact is disclosure of password hashes, followed by the possibility of logging in and carrying out authenticated operations against the database service. The provided CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, which aligns with a high-severity, remotely reachable issue affecting confidentiality, integrity, and availability.

Defensive priority

Immediate. This is a critical, unauthenticated, network-accessible issue with vendor-provided remediation available.

Recommended defensive actions

  • Update affected systems to Siemens TeleControl Server Basic V3.1.2.3 or later.
  • Restrict access to port 8000 on affected systems to trusted IP addresses only, as directed in the advisory.
  • Review exposure of any affected database-service interfaces and limit network reachability to the minimum necessary.
  • If the product is internet-facing or reachable from broader OT/IT networks, prioritize emergency change management and validate the update path before rollout.
  • Monitor for unexpected authentication events or database-service activity until remediation is complete.

Evidence notes

The supplied CISA CSAF source item for ICSA-25-289-09 states: "The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated operations of the database service." The same source lists Siemens TeleControl Server Basic V3.1 as the affected product and recommends restricting access to port 8000 to trusted IP addresses only, plus updating to V3.1.2.3 or later. The source references the Siemens advisory (ssa-062309) and the CISA advisory page for corroboration.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-40765 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-40765

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-40765 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-40765

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-289-09.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-062309.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-062309.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-289-09

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.