Siemens Telecontrol Server Basic vulnerabilities
77 known vulnerabilities affecting siemens/telecontrol_server_basic.
Total CVEs
77
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH69MEDIUM2LOW1
Vulnerabilities
Page 1 of 4
CVE-2024-44102P2CRITICALCVSS 10.0≥ 3.1, < 3.1.2.12024-11-12
CVE-2024-44102 [CRITICAL] CWE-502 CVE-2024-44102: A vulnerability has been identified in PP TeleControl Server Basic 1000 to 5000 V3.1 (6NH9910-0AA31-
A vulnerability has been identified in PP TeleControl Server Basic 1000 to 5000 V3.1 (6NH9910-0AA31-0AE1) (All versions < V3.1.2.1 with redundancy configured), PP TeleControl Server Basic 256 to 1000 V3.1 (6NH9910-0AA31-0AD1) (All versions < V3.1.2.1 with redundancy configured), PP TeleControl Server Basic 32 to 64 V3.1 (6NH9910-0AA31-0AF1) (All v
nvd
CVE-2025-27539P2CRITICALCVSS 9.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-27539 [CRITICAL] CWE-89 CVE-2025-27539: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'VerifyUser' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute cod
nvd
CVE-2025-27495P2CRITICALCVSS 9.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-27495 [CRITICAL] CWE-89 CVE-2025-27495: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateTrace' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute co
nvd
CVE-2025-27540P2CRITICALCVSS 9.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-27540 [CRITICAL] CWE-89 CVE-2025-27540: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'Authenticate' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute c
nvd
CVE-2025-40765P2CRITICALCVSS 9.8v3.1.2.22025-10-14
CVE-2025-40765 [CRITICAL] CWE-306 CVE-2025-40765: A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.
A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated operations of the database service.
nvd
CVE-2025-29905P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-29905 [HIGH] CWE-89 CVE-2025-29905: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'RestoreFromBackup' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute co
nvd
CVE-2025-31351P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-31351 [HIGH] CWE-89 CVE-2025-31351: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code w
nvd
CVE-2025-30002P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-30002 [HIGH] CWE-89 CVE-2025-30002: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateConnectionVariables' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and ex
nvd
CVE-2025-31349P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-31349 [HIGH] CWE-89 CVE-2025-31349: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateSmtpSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute c
nvd
CVE-2025-31350P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-31350 [HIGH] CWE-89 CVE-2025-31350: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateBufferingSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and exec
nvd
CVE-2025-31343P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-31343 [HIGH] CWE-89 CVE-2025-31343: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateTcmSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute co
nvd
CVE-2025-30030P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-30030 [HIGH] CWE-89 CVE-2025-30030: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ImportDatabase' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code
nvd
CVE-2025-30032P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-30032 [HIGH] CWE-89 CVE-2025-30032: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateDatabaseSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execu
nvd
CVE-2025-30003P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-30003 [HIGH] CWE-89 CVE-2025-30003: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateProjectConnections' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and exe
nvd
CVE-2025-30031P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-30031 [HIGH] CWE-89 CVE-2025-30031: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateUsers' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code wit
nvd
CVE-2025-32828P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32828 [HIGH] CWE-89 CVE-2025-32828: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateProjectCrossCommunications' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database
nvd
CVE-2025-32843P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32843 [HIGH] CWE-89 CVE-2025-32843: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockUser' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "
nvd
CVE-2025-32830P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32830 [HIGH] CWE-89 CVE-2025-32830: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code w
nvd
CVE-2025-32846P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32846 [HIGH] CWE-89 CVE-2025-32846: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockGeneralSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute
nvd
CVE-2025-32842P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32842 [HIGH] CWE-89 CVE-2025-32842: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetUsers' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "
nvd
1 / 4Next →