SQL Injection Vulnerability in TeleControl Server Basic by Siemens
CVE-2025-32837
8.7HIGH
What is CVE-2025-32837?
A vulnerability exists in TeleControl Server Basic, where the 'GetActiveConnectionVariables' method is susceptible to SQL injection attacks. This flaw allows an authenticated remote attacker to bypass authorization controls, potentially granting them access to read from and modify the application's database. If exploited, the attacker may execute arbitrary code with 'NT AUTHORITY\NetworkService' permissions, provided they have access to port 8000 of the affected system running a vulnerable version of the application.
Affected Version(s)
TeleControl Server Basic 0