A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated operations of the database service.
History

Tue, 14 Oct 2025 09:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated operations of the database service.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2025-10-14T09:15:16.351Z

Reserved: 2025-04-16T08:39:30.032Z

Link: CVE-2025-40765

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-14T10:15:38.127

Modified: 2025-10-14T10:15:38.127

Link: CVE-2025-40765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.