A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateTrace' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25911)
An attacker sends a specially crafted request to port 8000 of the TeleControl Server Basic service, exploiting the lack of input validation in the 'CreateTrace' method. Injection of malicious SQL code allows bypassing authorization mechanisms, reading and writing data in the application database, as well as executing code in the context of the 'NT AUTHORITY\NetworkService' account privileges. The attack is possible only when the attacker has network access to port 8000 of the system running the vulnerable version of the application.
An attacker can read and modify data in the application database, bypass authorization mechanisms, and execute code with the privileges of the 'NT AUTHORITY\NetworkService' account, which may lead to further system integrity violations.
Update Siemens TeleControl Server Basic to version V3.1.2.2 or later. Additionally, it is recommended to restrict network access to port 8000 exclusively to trusted hosts (e.g., through firewall or network segmentation), in accordance with the manufacturer's recommendations available at: https://cert-portal.siemens.com/productcert/html/ssa-443402.html
Siemens TeleControl Server Basic — all versions below V3.1.2.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSiemens Telecontrol Server Basic
APPSiemens< 3.1.2.2
Related vulnerabilities
Ujawnienie haseł i nieautoryzowany dostęp do bazy danych w Siemens TeleControl Server Basic
SQL Injection w Siemens TeleControl Server Basic – obejście autoryzacji i RCE
SQL Injection w Siemens TeleControl Server Basic — ominięcie autoryzacji i RCE
Siemens TeleControl Server Basic — niebezpieczna deserializacja umożliwiająca RCE z uprawnieniami SYSTEM
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected applicatio...