VORANT. Threat Intelligence Sign in Get the full feed

Siemens Desigo CC vulnerable to Client Code Execution

routine vulnerability manufacturinginfrastructure

A code-injection flaw in Siemens Desigo CC V6/V7 lets attackers execute arbitrary code on client machines via malicious graphics documents; no fix is currently available.

CISA republished a Siemens ProductCERT advisory (SSA-330084) describing a Client Code Execution vulnerability (CVE-2026-34223) in the Desigo CC building management product family, affecting all versions of V6 and V7. The flaw stems from insufficient input validation of scripts embedded in user-defined graphics documents. An attacker who crafts a malicious graphics document and convinces a privileged user to open it can trigger execution of embedded script code on the client application instance, enabling arbitrary file writes to the client OS. This could lead to full compromise of the client operating system and provide a foothold for lateral movement within the organization.

Exploitation requires social engineering (enticing a user to open a crafted document) and does not appear to have a known in-the-wild exploitation status per this advisory. No patch is currently available; Siemens recommends mitigating by restricting the graphics-editing authorization policy to least-privilege principles so only necessary users can create or modify graphics documents. General ICS hardening guidance also applies: isolate control system networks from business networks and the internet, use VPNs with care for any required remote access, and follow Siemens' operational guidelines for industrial security.

Affected sectors include Critical Manufacturing and Commercial Facilities, with worldwide deployment of Desigo CC building automation systems. The vulnerability was reported to Siemens by Michelin CERT. Defenders operating Desigo CC should audit who has access to create/modify graphics documents, restrict that capability, monitor for anomalous file-write activity on client systems, and watch for the release of an official Siemens patch.

Mentioned in this report

Vulnerabilities CVE-2026-34223

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-05

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free