Information Disclosure Vulnerability in TeleControl Server Basic by Siemens
CVE-2025-40765
9.3CRITICAL
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 14 October 2025
What is CVE-2025-40765?
A vulnerability in Siemens TeleControl Server Basic affects all versions between V3.1.2.2 and V3.1.2.3, enabling unauthenticated remote attackers to gain access to user password hashes. This excessive exposure of sensitive information could potentially allow attackers to log in and engage in unauthorized operations within the database service.
Affected Version(s)
TeleControl Server Basic V3.1 V3.1.2.2