CVE-2025-27127: Siemens Tia Project-Server
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project-Server V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions < V19 Update 4), Totally Integrated Automation Portal (TIA Portal) V20 (All versions < V20 Update 3). The affected application improperly handles uploaded projects in the document root. This could allow an attacker with contributor privileges to cause denial of service by uploading a malicious project.
Affected products
- Siemens Tia Project-Server: before V2.1.1 (fixed in V2.1.1)
- Siemens Tia Project-Server v17: any version
- Siemens Totally Integrated Automation Portal Tia Portal v17: any version
- Siemens Totally Integrated Automation Portal Tia Portal v18: any version
- Siemens Totally Integrated Automation Portal Tia Portal v19: before V19 Update 4 (fixed in V19 Update 4)
- Siemens Totally Integrated Automation Portal Tia Portal v20: before V20 Update 3 (fixed in V20 Update 3)
Published 2025-07-08. Last modified 2026-06-17.