news.mlab.sh
Back to the feed
vulnerability

Siemens Desigo CC family

HighCVSS 8.2
Summary

A Client Code Execution (CCE) vulnerability exists in Siemens Desigo CC family versions V6 and V7, allowing attackers to execute arbitrary code on client devices through malicious graphics documents. This vulnerability stems from insufficient input validation when handling scripts embedded within these documents. Exploitation requires a crafted graphics document, and successful attacks could lead to compromise of the client operating system and lateral movement within an organization. No fix is currently available.

A Client Code Execution (CCE) vulnerability has been identified in Siemens Desigo CC family versions V6 and V7, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it. This could lead to compromise of the client operating system and potential lateral movement within the organization.

The affected products are Siemens Desigo CC family, specifically versions V6 and V7.

Known Affected Countries/Areas Deployed: Worldwide

Company Headquarters Location: Germany

Relevant CWE: CWE-94 Improper Control of Generation of Code ('Code Injection')

Mitigation: Evaluate authorization policy for Graphics application following Least Privilege principle, so only required users have access to the configuration. No fix is currently available.

For more information, see the associated Siemens security advisory SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family - CSAF Version, and SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family - HTML Version.

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities, including minimizing network exposure for all control system devices and/or systems, and ensuring they are not accessible from the internet. Organizations should locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.

Read the full article at CISA Advisories