SQL Injection Vulnerability in TeleControl Server Basic by Siemens
CVE-2025-32838
8.7HIGH
What is CVE-2025-32838?
A security vulnerability exists in TeleControl Server Basic prior to version 3.1.2.2, which allows authenticated remote attackers to exploit the 'ImportConnectionVariables' method. This SQL injection flaw can lead to unauthorized access to the application's database, enabling attackers to read and write data or execute arbitrary code with elevated privileges. Successful exploitation requires access to port 8000 on the affected system, making it crucial for organizations to apply updates promptly to mitigate potential risks.
Affected Version(s)
TeleControl Server Basic 0