Siemens Desigo CC

Summary

A stack-based buffer overflow vulnerability (CVE-2025-15467) in OpenSSL, when used with certain CMS structures, can allow remote attackers to cause a denial of service or potentially execute remote code. Siemens has released updated versions of its Desigo CC product to address this issue and recommends immediate updates.

IFF Assessment

FOE

This vulnerability allows remote attackers to cause a denial of service or potentially execute code, posing a significant risk to systems, including critical infrastructure.

Severity

8.8 High

The CVSS score of 9.8 reflects the critical severity of this vulnerability. It allows for remote code execution with a low attack complexity and significant impact on confidentiality, integrity, and availability.

Defender Context

This article highlights a critical vulnerability in OpenSSL that impacts Siemens Desigo CC, a product used in critical manufacturing sectors. Defenders should prioritize updating affected Siemens Desigo CC installations to the latest versions and ensure their OpenSSL libraries are patched against CVE-2025-15467.

Read Full Story →