CVE-2025-40765

A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated operations of the database service.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:siemens:telecontrol_server_basic:3.1.2.2:*:*:*:*:*:*:*

History

21 Oct 2025, 14:40

Type Values Removed Values Added
CPE cpe:2.3:a:siemens:telecontrol_server_basic:3.1.2.2:*:*:*:*:*:*:*
References () https://cert-portal.siemens.com/productcert/html/ssa-062309.html - () https://cert-portal.siemens.com/productcert/html/ssa-062309.html - Vendor Advisory
First Time Siemens telecontrol Server Basic
Siemens

14 Oct 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-14 10:15

Updated : 2025-10-21 14:40


NVD link : CVE-2025-40765

Mitre link : CVE-2025-40765

CVE.ORG link : CVE-2025-40765


JSON object : View

Products Affected

siemens

  • telecontrol_server_basic
CWE
CWE-306

Missing Authentication for Critical Function