Cyber Resilience
← All news

Siemens Desigo CC

Our takeSiemens advisory ICSA-26-209-01 covers a stack-based buffer overflow in OpenSSL affecting Desigo CC and other products. Updates are available for several versions; more are coming. Update now if you run any of these systems.
Sources (2)
What this means for you — Security leader:If you run Siemens Desigo CC, update to the fixed versions Siemens has released and apply the interim countermeasures on any versions still awaiting fixes. OpenSSL stack overflow — treat as DoS with possible RCE until patched.
What this means for you — Lean IT orgs:Only matters if you run Siemens Desigo CC building-management software — update now if you do. Most shops without it can ignore this one.
What this means for you — MSP:Inventory client estates for Siemens Desigo CC; push the available fixed versions and apply Siemens’ interim countermeasures where a fix is still pending.
What this means for you — Researcher:CISA ICSA-26-209-01: OpenSSL stack-based buffer overflow in Siemens Desigo CC — remote DoS, possible RCE. Siemens shipping phased fixes; further versions still in prep.