CVE-2025-40765
🟠 Łataj w tym tygodniu
Ujawnienie informacji w TeleControl Server Basic pozwala na zdobycie haszy haseł użytkowników.
CVSS
9.8
EPSS
0.5%
Exploit
none
Vendor
siemens
Opis źródłowy (NVD)
A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated operations of the database service.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2025-10-14 10:15:38 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 12:10:00 UTC |
Referencje
- https://cert-portal.siemens.com/productcert/html/ssa-062309.html ([email protected]) [Vendor Advisory]