Our takeCISA reports a client code execution flaw in Siemens Desigo CC where malicious graphics documents can run embedded scripts on client systems. Siemens has issued updates. Patch now if you run Desigo CC.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA advisory ICSA-26-265-05 details a client code execution flaw in Siemens Desigo CC where malicious graphics documents can run embedded scripts on client systems. Apply the available updates immediately and restrict untrusted graphics files.
What this means for you — Lean IT orgs:If you run Siemens Desigo CC for building management, update to the patched version right away. Malicious graphics files could run code on your computers — only open files from trusted sources until you update.
What this means for you — MSP:Siemens Desigo CC clients should install the fixes from CISA advisory ICSA-26-265-05 on all affected management stations and client devices. Block or scan untrusted graphics documents until updates are complete across every managed site.
What this means for you — Researcher:CISA reports a client code execution vulnerability in the Siemens Desigo CC family via embedded scripts in user-defined graphics documents. Patches are available.