A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'VerifyUser' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25914)
The vulnerability results from insufficient input validation in the 'VerifyUser' method used internally by the application. An attacker can inject malicious SQL queries through port 8000, which must be accessible over the network. Successful exploitation of the vulnerability allows reading and writing to the application database and executing code in the context of the 'NT AUTHORITY\NetworkService' account. The attack requires no authentication or user interaction.
An attacker can completely bypass authorization mechanisms, gain unauthorized access to data in the application database (read and write), and execute arbitrary code with the privileges of the 'NT AUTHORITY\NetworkService' account on the server.
Update Siemens TeleControl Server Basic to version V3.1.2.2 or later. Additionally, it is recommended to restrict network access to port 8000 only to trusted hosts using a firewall or access control lists, in accordance with the manufacturer's recommendations: https://cert-portal.siemens.com/productcert/html/ssa-443402.html
Siemens TeleControl Server Basic – all versions below V3.1.2.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSiemens Telecontrol Server Basic
APPSiemens< 3.1.2.2
Related vulnerabilities
Ujawnienie haseł i nieautoryzowany dostęp do bazy danych w Siemens TeleControl Server Basic
SQL Injection w Siemens TeleControl Server Basic — nieautoryzowany dostęp i RCE
SQL Injection w Siemens TeleControl Server Basic — ominięcie autoryzacji i RCE
Siemens TeleControl Server Basic — niebezpieczna deserializacja umożliwiająca RCE z uprawnieniami SYSTEM
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected applicatio...