Siemens Telecontrol Server Basic vulnerabilities
77 known vulnerabilities affecting siemens/telecontrol_server_basic.
Total CVEs
77
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH69MEDIUM2LOW1
Vulnerabilities
Page 4 of 4
CVE-2025-32859P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32859 [HIGH] CWE-89 CVE-2025-32859: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockWebServerGatewaySettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and
nvd
CVE-2025-32860P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32860 [HIGH] CWE-89 CVE-2025-32860: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockWebServerGatewaySettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database a
nvd
CVE-2025-32855P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32855 [HIGH] CWE-89 CVE-2025-32855: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockOpcSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute co
nvd
CVE-2025-32861P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32861 [HIGH] CWE-89 CVE-2025-32861: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateTraceLevelSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and exe
nvd
CVE-2025-32856P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32856 [HIGH] CWE-89 CVE-2025-32856: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockBufferingSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execut
nvd
CVE-2025-32862P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32862 [HIGH] CWE-89 CVE-2025-32862: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockTraceLevelSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execu
nvd
CVE-2025-32858P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32858 [HIGH] CWE-89 CVE-2025-32858: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateWebServerGatewaySettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database a
nvd
CVE-2025-32868P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32868 [HIGH] CWE-89 CVE-2025-32868: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ExportCertificate' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute co
nvd
CVE-2025-32869P3HIGHCVSS 8.8fixed in 3.1.2.2fixed in V3.1.2.22025-04-16
CVE-2025-32869 [HIGH] CWE-89 CVE-2025-32869: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ImportCertificate' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute co
nvd
CVE-2018-4836P3HIGHCVSS 8.8fixed in 3.12018-01-25
CVE-2018-4836 [HIGH] CWE-287 CVE-2018-4836: A vulnerability has been identified in TeleControl Server Basic < V3.1. An authenticated attacker wi
A vulnerability has been identified in TeleControl Server Basic < V3.1. An authenticated attacker with a low-privileged account to the TeleControl Server Basic's port 8000/tcp could escalate his privileges and perform administrative operations.
nvd
CVE-2019-6575P3HIGHCVSS 7.5fixed in 3.1.1vAll versions < V3.1.12019-04-17
CVE-2019-6575 [HIGH] CWE-248 CVE-2019-6575: A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open
A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions = V2.5 < V2.6.1), SIMATIC S7-1500 Software Controller (All versions between V2.5 (including) and V2.7 (excluding)), SIMATIC WinCC OA (All versions < V3.15 P018), SIMATIC WinCC Runtime Advanc
nvd
CVE-2025-40942P3HIGHCVSS 7.8fixed in 3.1.2.4fixed in V3.1.2.42026-01-13
CVE-2025-40942 [HIGH] CWE-250 CVE-2025-40942: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains a local privilege escalation vulnerability that could allow an attacker to run arbitrary code with elevated privileges.
nvd
CVE-2018-4837P3HIGHCVSS 7.5fixed in 3.12018-01-25
CVE-2018-4837 [HIGH] CWE-400 CVE-2018-4837: A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with access to t
A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with access to the TeleControl Server Basic's webserver (port 80/tcp or 443/tcp) could cause a Denial-of-Service condition on the web server. The remaining functionality of the TeleControl Server Basic is not affected by the Denial-of-Service condition.
nvd
CVE-2021-40142P3HIGHCVSS 7.5v3.02021-08-27
CVE-2021-40142 [HIGH] CWE-119 CVE-2021-40142: In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a den
In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.
nvd
CVE-2018-4835P4MEDIUMCVSS 5.3fixed in 3.12018-01-25
CVE-2018-4835 [MEDIUM] CWE-287 CVE-2018-4835: A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network acc
A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with network access to the TeleControl Server Basic's port 8000/tcp could bypass the authentication mechanism and read limited information.
nvd
CVE-2021-45117P4MEDIUMCVSS 6.5v3.02022-03-21
CVE-2021-45117 [MEDIUM] CWE-476 CVE-2021-45117: The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can l
The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.
nvd
CVE-2025-29931P4LOWCVSS 3.7fixed in 3.1.2.2fixed in V3.1.2.22025-04-17
CVE-2025-29931 [LOW] CWE-130 CVE-2025-29931: A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected product does not properly validate a length field in a serialized message which it uses to determine the amount of memory to be allocated for deserialization. This could allow an unauthenticated remote attacker to cause the application to allocate ex
nvd
← Previous4 / 4