A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated operations of the database service.
The application lacks the required authentication mechanism before exposing sensitive data (CWE-306). An unauthenticated remote attacker can access a resource disclosing user password hashes without providing any credentials. The obtained hashes can be used directly or subjected to password cracking attacks, which opens the way to full authentication in the database service.
An attacker can obtain password hashes of user accounts, log in to the database service, and execute arbitrary operations requiring permissions in its context, which may lead to data disclosure, modification, or deletion.
Siemens TeleControl Server Basic must be updated to version V3.1.2.3 or later. Patch details are available in the vendor's advisory: https://cert-portal.siemens.com/productcert/html/ssa-062309.html
Siemens TeleControl Server Basic V3.1 — all versions >= V3.1.2.2 and < V3.1.2.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSiemens Telecontrol Server Basic
APPSiemens3.1.2.2
Related vulnerabilities
SQL Injection w Siemens TeleControl Server Basic – obejście autoryzacji i RCE
SQL Injection w Siemens TeleControl Server Basic — nieautoryzowany dostęp i RCE
SQL Injection w Siemens TeleControl Server Basic — ominięcie autoryzacji i RCE
Siemens TeleControl Server Basic — niebezpieczna deserializacja umożliwiająca RCE z uprawnieniami SYSTEM
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected applicatio...