Cyber Resilience
← All news
Confirmed

Siemens Desigo CC family

Our takeCISA reports a client code execution flaw in Siemens Desigo CC where malicious graphics documents can run embedded scripts on client instances. Siemens has released updates. Patch affected systems now.
Sources (1)
What this means for you — Security leader:Update all Desigo CC clients and servers to the versions listed in ICSA-26-265-05. The CISA advisory confirms this client code execution flaw is actively exploited via malicious graphics documents containing embedded scripts.
What this means for you — Lean IT orgs:If you run Siemens Desigo CC for building controls, apply the vendor updates right away. The vulnerability lets specially crafted graphics run code on any computer that opens them.
What this means for you — MSP:Check every client environment running Siemens Desigo CC and push the patches from ICSA-26-265-05 on an emergency cycle. CISA states the client code execution vulnerability is under active exploitation.
What this means for you — Researcher:CISA reports active exploitation of a client code execution vulnerability in the Siemens Desigo CC family via maliciously crafted graphics documents containing embedded scripts. Full details and patches are in ICSA-26-265-05.