VORANT. Threat Intelligence Sign in Get the full feed

Siemens Desigo CC hit by OpenSSL buffer overflow flaw

medium vulnerability manufacturing

A stack-based buffer overflow in OpenSSL's CMS AuthEnvelopedData parsing affects Siemens Desigo CC building automation software, risking DoS or code execution.

CISA republished a Siemens ProductCERT advisory detailing CVE-2025-15467, a stack-based buffer overflow (CWE-787) in OpenSSL's handling of CMS AuthEnvelopedData messages using AEAD ciphers such as AES-GCM. The flaw stems from an oversized IV in ASN.1 parameters being copied into a fixed-size stack buffer without length validation, allowing an attacker to trigger an out-of-bounds write before any authentication check occurs. Because the overflow happens pre-authentication, no valid key material is needed to trigger it, making the flaw exploitable purely through crafted input.

The vulnerability affects Siemens Desigo CC building automation platform versions V7, V8, and V9 prior to V9.0.1, deployed worldwide in critical manufacturing environments. Siemens has released fixes for V8 (patch V8.0 QU2.0021) and V9 (update to V9.0 QU1 or later), but no fix is currently available for V7. No exploitation in the wild is reported; this is a vendor-disclosed vulnerability advisory rather than an active campaign.

CISA and Siemens recommend standard ICS hardening measures — network segmentation, firewalling control system networks from business networks, avoiding direct internet exposure, and using VPNs for remote access — while affected organizations await or apply available patches. No threat actor or in-the-wild exploitation has been associated with this issue.

Mentioned in this report

Vulnerabilities CVE-2025-15467

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free