CVE-2025-40765
Telecontrol Server Basic vulnerability analysis and mitigation

Overview

A critical information disclosure vulnerability (CVE-2025-40765) was identified in TeleControl Server Basic V3.1 (versions >= V3.1.2.2 and < V3.1.2.3). The vulnerability was discovered and disclosed on October 14, 2025, affecting Siemens TeleControl Server Basic, a system that allows remote monitoring and control of plants via WAN/LAN (Siemens Advisory).

Technical details

The vulnerability allows an unauthenticated remote attacker to obtain password hashes of users and perform authenticated operations of the database service. It has been assigned CWE-306 (Missing Authentication for Critical Function). The vulnerability received a Critical severity rating with a CVSS v3.1 Base Score of 9.8 (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and a CVSS v4.0 Base Score of 9.3 (Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N) (Siemens Advisory).

Impact

The vulnerability could allow unauthorized access to user password hashes and enable attackers to perform authenticated database operations, potentially compromising the entire system's security. This poses significant risks to industrial control systems and plant operations that rely on TeleControl Server Basic (Cyble Report).

Mitigation and workarounds

Siemens has released version V3.1.2.3 to address this vulnerability and recommends users to update to this or a later version. As a temporary workaround, organizations can restrict access to port 8000 on affected systems to trusted IP addresses only. Siemens also recommends configuring the environment according to their operational guidelines for Industrial Security (Siemens Advisory).

Community reactions

The vulnerability has gained significant attention in the cybersecurity community, with researchers at Cyble including it in their weekly vulnerability report among other critical security issues. The discovery was coordinated with Tenable, demonstrating collaborative efforts in the security research community (Cyble Report).

Additional resources


SourceThis report was generated using AI

Related Telecontrol Server Basic vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40765CRITICAL9.3
  • Telecontrol Server Basic logoTelecontrol Server Basic
  • cpe:2.3:a:siemens:telecontrol_server_basic
NoNoOct 14, 2025
CVE-2025-32872HIGH8.7
  • Telecontrol Server Basic logoTelecontrol Server Basic
  • cpe:2.3:a:siemens:telecontrol_server_basic
NoYesApr 16, 2025
CVE-2025-30033HIGH8.5
  • Telecontrol Server Basic logoTelecontrol Server Basic
  • cpe:2.3:a:siemens:telecontrol_server_basic
NoYesAug 12, 2025
CVE-2025-40942HIGH7.3
  • Telecontrol Server Basic logoTelecontrol Server Basic
  • cpe:2.3:a:siemens:telecontrol_server_basic
NoYesJan 13, 2026
CVE-2025-29931MEDIUM6.3
  • Telecontrol Server Basic logoTelecontrol Server Basic
  • cpe:2.3:a:siemens:telecontrol_server_basic
NoYesApr 17, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management