Siemens TeleControl Server Basic
cpe:2.3:a:siemens:telecontrol_server_basic:*:*:*:*:*:*:*
- < V3.1.2.2
A SQL injection vulnerability has been identified in Siemens TeleControl Server Basic, affecting all versions prior to V3.1.2.2. The vulnerability arises in the 'CreateProject' method, allowing authenticated remote attackers to bypass authorization, manipulate the application's database, and execute code with 'NT AUTHORITY\NetworkService' permissions. Exploitation requires access to port 8000 on the affected system.
Exploitation of this vulnerability could lead to unauthorized database access, allowing attackers to read and write data. Additionally, it could enable code execution in the operating system's shell with limited 'NT AUTHORITY\NetworkService' permissions.
Users are advised to update to TeleControl Server Basic V3.1.2.2 or later. For specific update instructions, refer to the Siemens support page for TeleControl Server Basic. As an additional measure, restrict access to port 8000 on affected systems to trusted IP addresses only.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.