CVE-2025-27127: Malicious File Upload
A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project-Server V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions < V19 Update 4), Totally Integrated Automation Portal (TIA Portal) V20 (All versions < V20 Update 3). The affected application improperly handles uploaded projects in the document root. This could allow an attacker with contributor privileges to cause denial of service by uploading a malicious project.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27127?
CVE-2025-27127 is assessed with a high severity due to the potential for unauthorized access and control of affected systems.
How do I fix CVE-2025-27127?
To remediate CVE-2025-27127, users should update to TIA Project-Server version 2.1.1 or later and TIA Portal versions above V20 Update 3.
Which versions are affected by CVE-2025-27127?
CVE-2025-27127 affects TIA Project-Server versions before 2.1.1 and all TIA Portal versions up to V20 Update 3.
What systems are impacted by CVE-2025-27127?
CVE-2025-27127 impacts TIA Project-Server and several versions of Totally Integrated Automation Portal.
Is CVE-2025-27127 related to any specific type of attack?
CVE-2025-27127 is associated with vulnerabilities that may allow unauthorized remote access and control, posing risks for data integrity and availability.