These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2025-32831 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the CISA CSAF advisory and Siemens security notice, the flaw is in the internally used UpdateProjectUserRights method and can let an authenticated remote attacker bypass authorization controls, read from and write to the application's database, and execute code as NT AUTHORITY\\NetworkService. The advis [truncated]
CVE-2025-32830 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the CISA CSAF advisory, the flaw is reachable through the internally used UnlockProject method and can let an authenticated remote attacker bypass authorization controls, read and write the application's database, and execute code as NT AUTHORITY\NetworkService when the vulnerable service is reachable on port 8000.
CVE-2025-32829 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. The advisory states that an authenticated remote attacker who can reach port 8000 on a vulnerable system may abuse the internally used LockProjectCrossCommunications method to bypass authorization controls, read and write the application database, and potentially execute code as NT AUTHORITY\NetworkService.
CVE-2025-32827 is a high-severity vulnerability in Siemens TeleControl Server Basic. The issue is an SQL injection in the internally used ActivateProject method. According to the advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, and execute code with NT AUTHORITY\NetworkService permissions [truncated]
CVE-2025-32826 is a high-severity SQL injection affecting Siemens TeleControl Server Basic. According to the advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, and potentially execute code as NT AUTHORITY\\NetworkService. Siemens recommends restricting access to port 8000 and upgrading to V [truncated]
CVE-2025-32825 is a high-severity SQL injection issue affecting Siemens TeleControl Server Basic. According to the CISA/Siemens advisory published on 2025-04-16, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application database, and potentially execute code as NT AUTHORITY\NetworkService. Siemens and CISA updated the [truncated]
CVE-2025-32824 affects Siemens TeleControl Server Basic and is described as an SQL injection issue in the internally used UnlockProject method. According to the advisory, an authenticated remote attacker with network access to port 8000 on a vulnerable system could bypass authorization controls, read and write the application's database, and execute code as NT AUTHORITY\NetworkService. Siemens and CISA li [truncated]
CVE-2025-32823 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. An authenticated remote attacker who can reach port 8000 may bypass authorization controls, read and write the application's database, and execute code with NT AUTHORITY\\NetworkService permissions.
CVE-2025-32822 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the supplied CISA/Siemens advisory material, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, and potentially execute code as NT AUTHORITY\NetworkService. Siemens and CISA list remediation by upd [truncated]
CVE-2025-31353 is a Siemens TeleControl Server Basic SQL injection issue with CVSS 3.1 8.8 (HIGH). According to the CISA CSAF advisory and Siemens product advisory, the flaw is in the internally used UpdateOpcSettings method. An authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, and execute code as NT A [truncated]
CVE-2025-31352 is a high-severity SQL injection vulnerability in Siemens TeleControl Server Basic. According to the advisory, an authenticated remote attacker who can reach port 8000 may bypass authorization controls, read and write the application database, and potentially execute code as NT AUTHORITY\NetworkService. Siemens and CISA recommend restricting access to port 8000 and updating to version V3.1. [truncated]
CVE-2025-31351 affects Siemens TeleControl Server Basic and was published on 2025-04-16. The advisory says an authenticated remote attacker who can reach port 8000 on a vulnerable system may abuse SQL injection in the internally used CreateProject method to bypass authorization, read and write the application database, and potentially execute code as NT AUTHORITY\NetworkService. Siemens lists an update to [truncated]
CVE-2025-31350 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the CISA/Siemens advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, and execute code as NT AUTHORITY\NetworkService. Siemens and CISA published the advisory on 2025-04-16 and later revise [truncated]
CVE-2025-31349 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and modify the application database, and potentially execute code as NT AUTHORITY\NetworkService.
CVE-2025-31343 is a high-severity SQL injection issue in Siemens TeleControl Server Basic, disclosed on 2025-04-16 and later revised on 2025-05-06 for typo fixes. The flaw is in the internally used UpdateTcmSettings method and can let an authenticated remote attacker bypass authorization controls, access the database, and potentially execute code as NT AUTHORITY\NetworkService if the vulnerable service is [truncated]
CVE-2025-30032 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the CISA/Siemens advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may abuse the internally used UpdateDatabaseSettings method to bypass authorization controls, read and write the application's database, and potentially execute code as NT AUTHORITY\NetworkService. [truncated]
CVE-2025-30031 affects Siemens TeleControl Server Basic and is described by CISA and Siemens as an SQL injection flaw in the internally used UpdateUsers method. An authenticated remote attacker with access to port 8000 can bypass authorization controls, read and write the application database, and execute code in the NT AUTHORITY\NetworkService context. The supplied advisory data lists this as a High-seve [truncated]
CVE-2025-30030 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the CISA/Siemens advisory, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the application's database, and execute code as NT AUTHORITY\NetworkService. Siemens lists an update to version V3.1.2.2 or later and recommends re [truncated]
CVE-2025-30003 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the CISA/Siemens advisory, the flaw is reachable through the internally used UpdateProjectConnections method and can let an authenticated remote attacker bypass authorization controls, read and write the application database, and potentially execute code as NT AUTHORITY\NetworkService. The advisory note [truncated]
CVE-2025-30002 is a high-severity SQL injection issue in Siemens TeleControl Server Basic. According to the CISA CSAF advisory, the flaw is in the internally used UpdateConnectionVariables method and can let an authenticated remote attacker bypass authorization controls, read from and write to the application's database, and execute code as NT AUTHORITY\NetworkService. Successful exploitation requires net [truncated]
CVE-2025-29931 is a low-severity issue in Siemens TeleControl Server Basic where a serialized message length field is not properly validated, allowing memory exhaustion during deserialization. The impact is a partial denial of service, not code execution or data compromise. Exploitation is narrowly constrained: it is described as possible only in redundant Telecontrol Server Basic setups and only when the [truncated]
CVE-2025-29905 is a high-severity SQL injection vulnerability affecting Siemens TeleControl Server Basic. According to the CISA/Siemens advisory corpus, an authenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and modify the application's database, and execute code with NT AUTHORITY\NetworkService permissions. The advisory was published on 202 [truncated]
CVE-2025-27540 is a critical SQL injection issue in Siemens TeleControl Server Basic. According to the advisory, a remote unauthenticated attacker who can reach TCP port 8000 may bypass authorization controls, read and write the application database, and execute code as NT AUTHORITY\NetworkService. Siemens lists an update to V3.1.2.2 or later and access restriction for port 8000 as the primary mitigations.
CVE-2025-27539 is a critical SQL injection issue in Siemens TeleControl Server Basic. According to the CISA/Siemens advisory, an unauthenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization, read and write the application's database, and potentially execute code as NT AUTHORITY\NetworkService. The advisory was published on 2025-04-16 and later revised on 2025-05- [truncated]
CVE-2025-27495 is a critical Siemens TeleControl Server Basic issue involving SQL injection in the internally used CreateTrace method. According to the supplied CISA/Siemens advisory material, an unauthenticated remote attacker who can reach port 8000 on a vulnerable system may bypass authorization controls, read and write the database, and execute code as NT AUTHORITY\\NetworkService. Siemens and CISA li [truncated]
CVE-2025-3576 is a medium-severity integrity vulnerability affecting Siemens RUGGEDCOM ROX products when MIT Kerberos GSSAPI messages use RC4-HMAC-MD5. According to the advisory, weaknesses in MD5 checksum design can let an attacker spoof protected messages and forge message integrity codes when RC4 is preferred over stronger encryption types. Siemens and CISA identify affected RUGGEDCOM ROX MX5000 and re [truncated]
CVE-2025-30280 is a medium-severity information disclosure issue in Siemens Mendix Runtime-based applications. CISA and Siemens state that certain client actions can produce distinguishable responses, allowing an unauthenticated remote attacker to enumerate valid entities and attribute names. The advisory was published on 2025-04-08 and later revised on 2025-06-10 to add a fix for Mendix Runtime V8.
CVE-2025-30000 affects Siemens License Server (SLS) and can allow a low-privileged attacker to escalate privileges because user permissions are not properly restricted. The issue was published on 2025-04-08 and later revised on 2025-05-06 for typos only. Siemens’ remediation in the supplied advisory is to update to V4.3 or later.
CVE-2025-29999 affects Siemens License Server (SLS). According to the advisory, the application searches for executable files in its application folder without proper validation. In a successful abuse scenario, an attacker who can place a malicious executable in that same directory may achieve arbitrary code execution with administrative privileges on the affected system. Siemens lists an update to V4.3 o [truncated]
On 2025-04-08, CISA published advisory ICSA-25-100-05 for Siemens Insights Hub Private Cloud regarding CVE-2025-24514. The issue is in ingress-nginx: the `auth-url` Ingress annotation can be used to inject configuration into nginx, which may result in arbitrary code execution in the ingress-nginx controller context and disclosure of Secrets accessible to that controller. In the default installation, the c [truncated]