VYPR
advisoryPublished Sep 22, 2026· 1 source

Siemens Desigo CC Vulnerability Allows Client Code Execution

A critical Client Code Execution vulnerability in Siemens Desigo CC versions V6 and V7 could allow attackers to execute arbitrary code on client devices by crafting malicious graphics documents.

Siemens' Desigo CC building management system is affected by a critical Client Code Execution (CCE) vulnerability, identified as CVE-2026-34223. This flaw could enable attackers to execute arbitrary code on client devices by tricking users into opening specially crafted graphics documents embedded with malicious scripts.

The vulnerability stems from insufficient input validation when the Desigo CC application handles scripts within user-defined graphics. Attackers can create or modify these graphics documents to include malicious commands. When a user opens such a document on a client application instance, the embedded script is executed, potentially allowing an attacker to write arbitrary files to the client's operating system.

Successful exploitation requires an attacker to first craft a malicious graphics document and then persuade a user with adequate privileges to view it. The potential impact includes a full compromise of the client operating system. This compromise can then serve as a pivot point for attackers to move laterally within the organization's network, escalating their access and control.

Siemens has confirmed that Desigo CC family versions V6 and V7 are affected. Currently, no patch or fix is available for this vulnerability. The company strongly recommends evaluating and enforcing strict authorization policies for the Graphics application, adhering to the principle of least privilege, to limit which users can access its configuration.

The vulnerability has been assigned a CVSS v3.1 base score of 8.2 (High), with a vector string of CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H. This indicates that while exploitation requires local access, low privileges, and user interaction, the potential impact on confidentiality, integrity, and availability is high, with a significant system-wide consequence.

Michelin CERT is credited with reporting this vulnerability to Siemens. In addition to the specific mitigation advice for the Graphics application, Siemens generally advises protecting network access to all industrial control system devices with appropriate security mechanisms. Organizations are encouraged to configure their IT environments according to Siemens' operational guidelines for Industrial Security and to follow product manual recommendations.

CISA, which published the advisory, also recommends minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating them behind firewalls, isolated from business networks. When remote access is necessary, secure methods like VPNs should be employed, with the caveat that VPNs themselves must be kept updated and are only as secure as their connected endpoints.

This advisory underscores the ongoing risks associated with vulnerabilities in industrial control systems (ICS) and building management systems, where a compromise of a client device can lead to broader network infiltration. The reliance on user interaction for exploitation highlights the importance of security awareness training alongside technical mitigations.

Synthesized by Vypr AI
Siemens Desigo CC Vulnerability Allows Client Code Execution · VYPR