Siemens Desigo CC family

Summary

A Client Code Execution (CCE) vulnerability, identified as CVE-2026-34223, has been discovered in Siemens Desigo CC versions V6 and V7. This vulnerability allows attackers to execute arbitrary code on client devices by embedding malicious scripts within specially crafted graphics documents, potentially leading to operating system compromise and lateral movement.

IFF Assessment

FOE

The vulnerability allows for arbitrary code execution, which is a significant threat to system integrity and data security.

Severity

8.2 High

Defender Context

This vulnerability in Siemens Desigo CC, a system used in critical infrastructure like manufacturing and commercial facilities, poses a substantial risk. Defenders should prioritize patching or implementing compensating controls for affected versions to prevent client code execution. Organizations should also be vigilant about user training to recognize and avoid opening untrusted graphics documents that could contain malicious scripts.

Read Full Story →