CVE-2025-40942

8.8

Siemens · TeleControl Server Basic

Siemens TeleControl Server Basic contains a local privilege escalation vulnerability allowing attackers to execute arbitrary code with elevated privileges.

Executive summary

A local privilege escalation flaw in Siemens TeleControl Server Basic allows an attacker to achieve code execution with elevated system privileges, posing a significant risk to industrial control systems.

Vulnerability

The application is susceptible to a local privilege escalation vulnerability, categorized as CWE-250 (Execution with Unnecessary Privileges), which permits an attacker with local access to execute arbitrary code with higher privileges than intended.

Business impact

Successful exploitation allows a local attacker to gain full control over the affected server, potentially leading to unauthorized data access, system disruption, or the compromise of industrial control processes. With a CVSS score of 8.8, this vulnerability represents a high-severity risk that could lead to complete system compromise if an attacker establishes a foothold on the host.

Remediation

Immediate Action: Update Siemens TeleControl Server Basic to version V3.1.2.4 or later as specified in the vendor security advisory.

Proactive Monitoring: Monitor server logs for unusual process execution patterns or unauthorized attempts to access administrative functions.

Compensating Controls: Restrict local access to the server to authorized personnel only, and implement strict endpoint security policies to prevent unauthorized code execution.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Given the critical nature of industrial control environments, it is imperative to prioritize this update to mitigate the risk of privilege escalation. Organizations should verify their current version of TeleControl Server Basic and apply the V3.1.2.4 patch immediately to eliminate the underlying vulnerability.

More Siemens CVEs

Sources