A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'Authenticate' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25913)
The vulnerability results from insufficient input data sanitization in the internal 'Authenticate' method of the application. An unauthenticated remote attacker with access to TCP port 8000 on a system running a vulnerable version of the software can inject malicious SQL code. This allows bypassing access control mechanisms, reading and writing data in the application database, and executing code with the privileges of the 'NT AUTHORITY\NetworkService' account.
An attacker can gain unauthorized access to the application database (read and write), bypass authentication mechanisms, and execute arbitrary code with the privileges of the system network account 'NT AUTHORITY\NetworkService', which may lead to further system compromise.
Siemens TeleControl Server Basic should be updated to version V3.1.2.2 or later. As a temporary security measure, access to TCP port 8000 should be restricted to trusted hosts only using a firewall or network segmentation. Details are available in the manufacturer's bulletin: https://cert-portal.siemens.com/productcert/html/ssa-443402.html
Siemens TeleControl Server Basic — all versions below V3.1.2.2 with TCP port 8000 accessible.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSiemens Telecontrol Server Basic
APPSiemens< 3.1.2.2
Related vulnerabilities
Ujawnienie haseł i nieautoryzowany dostęp do bazy danych w Siemens TeleControl Server Basic
SQL Injection w Siemens TeleControl Server Basic — nieautoryzowany dostęp i RCE
SQL Injection w Siemens TeleControl Server Basic – obejście autoryzacji i RCE
Siemens TeleControl Server Basic — niebezpieczna deserializacja umożliwiająca RCE z uprawnieniami SYSTEM
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected applicatio...