These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2025-32864 affects Siemens TeleControl Server Basic and is described by CISA as an SQL injection issue in the internally used GetSettings method. A successful attack requires authenticated access and reachability of port 8000 on a system running a vulnerable version. If exploited, the flaw could let an attacker bypass authorization controls, read and write the application database, and execute code wi [truncated]
CVE-2025-32862 affects Siemens TeleControl Server Basic and was published on 2025-04-16, with a later advisory revision on 2025-05-06 for typo fixes only. The issue is an authenticated SQL injection in the internally used LockTraceLevelSettings method. According to the advisory, a successful attack can bypass authorization controls, read and write the application's database, and execute code as NT AUTHORI [truncated]
CVE-2025-32861 is a high-severity vulnerability in Siemens TeleControl Server Basic. According to the CISA/Siemens advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may exploit SQL injection in the internally used UpdateTraceLevelSettings method to bypass authorization controls, read and write the application's database, and execute code as NT AUTHORITY\NetworkService.
CVE-2025-32859 is a Siemens TeleControl Server Basic vulnerability that can let an authenticated remote attacker abuse SQL injection in the internally used LockWebServerGatewaySettings method. The advisory says the issue can bypass authorization controls, read and write the application database, and execute code as NT AUTHORITY\NetworkService when the vulnerable service is reachable on port 8000. Siemens' [truncated]
CVE-2025-32858 affects Siemens TeleControl Server Basic and was publicly disclosed on 2025-04-16. The advisory describes an SQL injection issue in the internally used UpdateWebServerGatewaySettings method. An authenticated remote attacker with access to port 8000 on a vulnerable system could bypass authorization controls, read and write the application's database, and execute code with NT AUTHORITY\Networ [truncated]
CVE-2025-32857 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the CISA/Siemens advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, and potentially execute code as NT AUTHORITY\NetworkService. Siemens lists an update to V3.1.2.2 or later as the vendor [truncated]
CVE-2025-32856 is a high-severity SQL injection vulnerability in Siemens TeleControl Server Basic. According to the published advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, interact with the application's database, and potentially execute code as NT AUTHORITY\NetworkService. Siemens and CISA published the advisory on 2025-04-16, [truncated]
CVE-2025-32855 affects Siemens TeleControl Server Basic. The supplied CISA/Siemens advisory says the internally used UnlockOpcSettings method is vulnerable to SQL injection. An authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, and execute code with NT AUTHORITY\NetworkService permissions. Siemens' reme [truncated]
CVE-2025-32854 affects Siemens TeleControl Server Basic and was published on 2025-04-16. CISA and Siemens describe an SQL injection in the internally used LockOpcSettings method. If an authenticated remote attacker can reach port 8000 on a vulnerable system, they may bypass authorization controls, read and write the application's database, and execute code with NT AUTHORITY\NetworkService permissions. Sie [truncated]
CVE-2025-32853 affects Siemens TeleControl Server Basic and was published on 2025-04-16, with a later 2025-05-06 revision noted as typo fixes. The advisory describes an SQL injection vulnerability in the internally used UnlockDatabaseSettings method. An authenticated remote attacker who can reach port 8000 on a vulnerable system may be able to bypass authorization controls, read from and write to the appl [truncated]
CVE-2025-32851 is a high-severity SQL injection vulnerability affecting Siemens TeleControl Server Basic. According to the public advisory published on 2025-04-16 and revised on 2025-05-06, an authenticated remote attacker who can access port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, and potentially execute code with NT AUTHORITY\NetworkServi [truncated]
CVE-2025-32850 is a high-severity SQL injection vulnerability in Siemens TeleControl Server Basic. According to the CISA/Siemens advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, and execute code as NT AUTHORITY\NetworkService. Siemens advises updating to V3.1.2.2 or later and restricting [truncated]
CVE-2025-32849 affects Siemens TeleControl Server Basic and was publicly disclosed on 2025-04-16. The advisory says an authenticated remote attacker who can reach port 8000 on a vulnerable system may abuse SQL injection in the internally used UnlockSmtpSettings method to bypass authorization controls, access the application's database, and potentially execute code with NT AUTHORITY\NetworkService permissions.
CVE-2025-32848 affects Siemens TeleControl Server Basic and is described by CISA as an SQL injection flaw in the internally used LockSmtpSettings method. The advisory says an authenticated remote attacker who can access port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, and execute code as NT AUTHORITY\NetworkService. Siemens and CISA list a vend [truncated]
CVE-2025-32847 affects Siemens TeleControl Server Basic and was publicly disclosed on 2025-04-16 in CISA advisory ICSA-25-112-01 / Siemens advisory SSA-443402. The issue is an SQL injection in the internally used UnlockGeneralSettings method; an authenticated remote attacker who can reach port 8000 may bypass authorization controls, read and write the application's database, and execute code as NT AUTHORI [truncated]
CVE-2025-32846 is a high-severity SQL injection vulnerability in Siemens TeleControl Server Basic. The advisory says the issue is in the internally used LockGeneralSettings method and can let an authenticated remote attacker bypass authorization controls, read and write the application database, and execute code as NT AUTHORITY\NetworkService. A successful attack also requires access to port 8000 on a sys [truncated]
CVE-2025-32845 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the advisory, an authenticated remote attacker who can reach port 8000 may bypass authorization controls, read and write the application's database, and execute code as NT AUTHORITY\NetworkService.
CVE-2025-32844 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the CISA/Siemens advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application database, and execute code with NT AUTHORITY\NetworkService permissions. Siemens identifies V3.1.2.2 or later as the fixed release.
CVE-2025-32843 affects Siemens TeleControl Server Basic and was publicly disclosed on 2025-04-16, with a later 2025-05-06 revision for typo fixes only. The issue is an SQL injection in the internally used LockUser method. According to the advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, a [truncated]
CVE-2025-32842 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the CISA/Siemens advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application database, and potentially execute code as NT AUTHORITY\NetworkService. Siemens and CISA list an update to V3.1.2.2 or later and res [truncated]
CVE-2025-32841 affects Siemens TeleControl Server Basic and is described by CISA as an SQL injection issue in the internally used UnlockGateway method. An authenticated remote attacker with access to port 8000 on a vulnerable system may be able to bypass authorization controls, read and write the application's database, and execute code as NT AUTHORITY\NetworkService.
CVE-2025-32840 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the CISA/Siemens advisory, an authenticated remote attacker who can reach port 8000 on a system running a vulnerable version may bypass authorization controls, read from and write to the application's database, and potentially execute code with NT AUTHORITY\NetworkService permissions. Siemens and CISA l [truncated]
CVE-2025-32839 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. An authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, and execute code as NT AUTHORITY\NetworkService.
CVE-2025-32838 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the CISA/Siemens advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application database, and potentially execute code as NT AUTHORITY\NetworkService. Siemens recommends updating to V3.1.2.2 or later and restric [truncated]
CVE-2025-32837 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the advisory, an authenticated remote attacker who can reach the application on port 8000 may bypass authorization controls, read and write the application's database, and potentially execute code with NT AUTHORITY\NetworkService permissions. Siemens and CISA list a vendor fix in V3.1.2.2 or later and r [truncated]
CVE-2025-32836 affects Siemens TeleControl Server Basic and is described by CISA as an SQL injection issue in the internally used GetConnectionVariables method. An authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application database, and execute code as NT AUTHORITY\NetworkService.
CVE-2025-32835 is a high-severity SQL injection issue in Siemens TeleControl Server Basic, exposed through the internally used UpdateConnectionVariableArchivingBuffering method. According to the advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable host may bypass authorization controls, read and write the application's database, and execute code as NT AUTHORITY\NetworkService [truncated]
CVE-2025-32834 is a high-severity SQL injection issue in Siemens TeleControl Server Basic, exposed through the internally used UpdateConnectionVariablesWithImport method. According to the public advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, and execute code as NT AUTHORITY\NetworkServi [truncated]
CVE-2025-32833 is a high-severity SQL injection vulnerability in Siemens TeleControl Server Basic. According to the CISA CSAF advisory and Siemens security advisory, the flaw affects the internally used UnlockProjectUserRights method and can let an authenticated remote attacker bypass authorization controls, read and write the application database, and execute code as NT AUTHORITY\\NetworkService. The ven [truncated]
CVE-2025-32832 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the CISA CSAF advisory and Siemens product security advisory, the flaw is in the internally used LockProjectUserRights method and can let an authenticated remote attacker bypass authorization controls, access the application database for read/write operations, and execute code with NT AUTHORITY\NetworkS [truncated]