vciy

Siemens TeleControl Server Basic: 67 records in one advisory

67 records announced together, published 2025-04-16, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://cert-portal.siemens.com/productcert/html/ssa-443402.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

65 of 67 records name something of its own. For the other 2, held sources say the same thing about each.

Most commonly mapped weakness across the batch: CWE-89: Improper Neutralization of Special…

What this page does not cover

Every record citing this advisory is on this page.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

16 outside reports led Siemens to search its own code for the same pattern

Trend Micro's Zero Day Initiative reported the first of these to Siemens on 21 February 2025, an injection flaw reachable through the Authenticate method of TeleControl Server Basic, tracked internally as ZDI-CAN-25913 and scored 9.8. Siemens then went looking for the rest itself. Its advisory says the company "conducted a root-cause analysis for potential SQL injection vulnerabilities and has identified the locations in the code base where the underlying legacy design pattern has been used". The result is one advisory covering 67 separate injection findings in a single product, which is why so many of these records read alike. Siemens' advisory says version 3.1.2.2 of that product addresses the identifiers it lists. The United States Cybersecurity and Infrastructure Security Agency republished the set on 22 April 2025 as ICSA-25-112-01, stated plainly that "Siemens reported these vulnerabilities to CISA", and listed by name the 16 identifiers the Zero Day Initiative coordinated, so a reader can count them. The descriptions themselves are the most specific thing in the set, because each one names the method it reaches, such as CreateTrace or Authenticate.

The record you are reading names one method in one product, and 66 others were announced beside it on the same day. Sixteen of the 67 came in from outside and CISA names which sixteen, so you can check whether this one is among them. The rest came out of Siemens reading its own code for one recurring pattern, and each remains its own entry.

2025-02-21The Zero Day Initiative reports the Authenticate method flaw, later CVE-2025-27540, to Siemens
2025-04-16Siemens publishes SSA-443402 and names version 3.1.2.2 as the release that addresses it
2025-04-22CISA republishes the set as ICSA-25-112-01, counting 67 identifiers and naming the 16 coordinated by the Zero Day Initiative
2025-06-16The Zero Day Initiative releases its own advisory for CVE-2025-27540

Siemens does not mark which 51 of the 67 came from its own review, so the split has to be worked out by subtracting the 16 CISA names. The outside report that started it credits an anonymous researcher rather than a person. Nothing in either advisory says whether any of these was ever used against a real system, and the descriptions name a method without saying which product feature reaches it.

Written from cert-portal.siemens.com, cisa.gov, zerodayinitiative.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2025-27495createtraceCWE-89: Improper Neutralization of Special…
CVE-2025-27539verifyuserCWE-89: Improper Neutralization of Special…
CVE-2025-27540authenticateCWE-89: Improper Neutralization of Special…
CVE-2025-29905restorefrombackupCWE-89: Improper Neutralization of Special…
CVE-2025-30002updateconnectionvariablesCWE-89: Improper Neutralization of Special…
CVE-2025-30003updateprojectconnectionsCWE-89: Improper Neutralization of Special…
CVE-2025-30030importdatabaseCWE-89: Improper Neutralization of Special…
CVE-2025-30031updateusersCWE-89: Improper Neutralization of Special…
CVE-2025-30032updatedatabasesettingsCWE-89: Improper Neutralization of Special…
CVE-2025-31343updatetcmsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-31349updatesmtpsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-31350updatebufferingsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-31351createprojectCWE-89: Improper Neutralization of Special…
CVE-2025-31352updategatewaysCWE-89: Improper Neutralization of Special…
CVE-2025-31353updateopcsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32475updateprojectCWE-89: Improper Neutralization of Special…
CVE-2025-32822deleteprojectCWE-89: Improper Neutralization of Special…
CVE-2025-32823lockprojectCWE-89: Improper Neutralization of Special…
CVE-2025-32824no title heldCWE-89: Improper Neutralization of Special…
CVE-2025-32825getprojectsCWE-89: Improper Neutralization of Special…
CVE-2025-32826getactiveprojectsCWE-89: Improper Neutralization of Special…
CVE-2025-32827activateprojectCWE-89: Improper Neutralization of Special…
CVE-2025-32828updateprojectcrosscommunicationsCWE-89: Improper Neutralization of Special…
CVE-2025-32829lockprojectcrosscommunicationsCWE-89: Improper Neutralization of Special…
CVE-2025-32830no title heldCWE-89: Improper Neutralization of Special…
CVE-2025-32831updateprojectuserrightsCWE-89: Improper Neutralization of Special…
CVE-2025-32832lockprojectuserrightsCWE-89: Improper Neutralization of Special…
CVE-2025-32833unlockprojectuserrightsCWE-89: Improper Neutralization of Special…
CVE-2025-32834updateconnectionvariableswithimportCWE-89: Improper Neutralization of Special…
CVE-2025-32835updateconnectionvariablearchivingbufferingCWE-89: Improper Neutralization of Special…
CVE-2025-32836getconnectionvariablesCWE-89: Improper Neutralization of Special…
CVE-2025-32837getactiveconnectionvariablesCWE-89: Improper Neutralization of Special…
CVE-2025-32838importconnectionvariablesCWE-89: Improper Neutralization of Special…
CVE-2025-32839getgatewaysCWE-89: Improper Neutralization of Special…
CVE-2025-32840lockgatewayCWE-89: Improper Neutralization of Special…
CVE-2025-32841unlockgatewayCWE-89: Improper Neutralization of Special…
CVE-2025-32842getusersCWE-89: Improper Neutralization of Special…
CVE-2025-32843lockuserCWE-89: Improper Neutralization of Special…
CVE-2025-32844unlockuserCWE-89: Improper Neutralization of Special…
CVE-2025-32845updategeneralsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32846lockgeneralsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32847unlockgeneralsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32848locksmtpsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32849unlocksmtpsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32850locktcmsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32851unlocktcmsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32852lockdatabasesettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32853unlockdatabasesettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32854lockopcsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32855unlockopcsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32856lockbufferingsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32857unlockbufferingsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32858updatewebservergatewaysettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32859lockwebservergatewaysettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32860unlockwebservergatewaysettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32861updatetracelevelsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32862locktracelevelsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32863unlocktracelevelsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32864getsettingsCWE-89: Improper Neutralization of Special…
CVE-2025-32865createlogCWE-89: Improper Neutralization of Special…
CVE-2025-32866getlogsCWE-89: Improper Neutralization of Special…
CVE-2025-32867createbackupCWE-89: Improper Neutralization of Special…
CVE-2025-32868exportcertificateCWE-89: Improper Neutralization of Special…
CVE-2025-32869importcertificateCWE-89: Improper Neutralization of Special…
CVE-2025-32870gettracesCWE-89: Improper Neutralization of Special…
CVE-2025-32871migratedatabaseCWE-89: Improper Neutralization of Special…
CVE-2025-32872getoverviewCWE-89: Improper Neutralization of Special…

67 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.