cbcvebase.

Siemens Telecontrol Server Basic vulnerabilities

77 known vulnerabilities affecting siemens/telecontrol_server_basic.

Total CVEs
77
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH69MEDIUM2LOW1

Vulnerabilities

Page 2 of 4
CVE-2025-32844P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32844 [HIGH] CWE-89 CVE-2025-32844: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockUser' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with
nvd
CVE-2025-32838P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32838 [HIGH] CWE-89 CVE-2025-32838: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ImportConnectionVariables' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and ex
nvd
CVE-2025-32831P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32831 [HIGH] CWE-89 CVE-2025-32831: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateProjectUserRights' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and exec
nvd
CVE-2025-32829P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32829 [HIGH] CWE-89 CVE-2025-32829: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockProjectCrossCommunications' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database a
nvd
CVE-2025-31352P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-31352 [HIGH] CWE-89 CVE-2025-31352: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateGateways' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code
nvd
CVE-2025-32833P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32833 [HIGH] CWE-89 CVE-2025-32833: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockProjectUserRights' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and exec
nvd
CVE-2025-32837P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32837 [HIGH] CWE-89 CVE-2025-32837: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetActiveConnectionVariables' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and
nvd
CVE-2025-32841P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32841 [HIGH] CWE-89 CVE-2025-32841: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockGateway' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code w
nvd
CVE-2025-32826P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32826 [HIGH] CWE-89 CVE-2025-32826: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetActiveProjects' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute co
nvd
CVE-2025-32825P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32825 [HIGH] CWE-89 CVE-2025-32825: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetProjects' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code wit
nvd
CVE-2025-31353P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-31353 [HIGH] CWE-89 CVE-2025-31353: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateOpcSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute co
nvd
CVE-2025-32835P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32835 [HIGH] CWE-89 CVE-2025-32835: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateConnectionVariableArchivingBuffering' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application'
nvd
CVE-2025-32823P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32823 [HIGH] CWE-89 CVE-2025-32823: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code wit
nvd
CVE-2025-32836P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32836 [HIGH] CWE-89 CVE-2025-32836: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetConnectionVariables' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execu
nvd
CVE-2025-32847P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32847 [HIGH] CWE-89 CVE-2025-32847: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockGeneralSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execut
nvd
CVE-2025-32832P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32832 [HIGH] CWE-89 CVE-2025-32832: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockProjectUserRights' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execut
nvd
CVE-2025-32834P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32834 [HIGH] CWE-89 CVE-2025-32834: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateConnectionVariablesWithImport' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's datab
nvd
CVE-2025-32827P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32827 [HIGH] CWE-89 CVE-2025-32827: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ActivateProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code
nvd
CVE-2025-32824P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32824 [HIGH] CWE-89 CVE-2025-32824: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code w
nvd
CVE-2025-32840P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32840 [HIGH] CWE-89 CVE-2025-32840: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockGateway' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code wit
nvd
Siemens Telecontrol Server Basic vulnerabilities | cvebase