Siemens TeleControl Server Basic
cpe:2.3:a:siemens:telecontrol_server_basic:*:*:*:*:*:*:*
- >= V3.1.2.2, < V3.1.2.3
An information disclosure vulnerability has been identified in Siemens TeleControl Server Basic version 3.1, specifically in all versions from 3.1.2.2 up to but not including 3.1.2.3. This vulnerability allows an unauthenticated remote attacker to access password hashes of users, potentially leading to unauthorized login and execution of authenticated operations within the database service.
Exploitation of this vulnerability could result in unauthorized access to user accounts, allowing attackers to log in and perform authenticated actions on the database service.
Users are advised to update to version 3.1.2.3 or a later version. For more information, visit the Siemens support page for TeleControl Server Basic. Additionally, restrict access to port 8000 on affected systems to trusted IP addresses only.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.