CISA

Siemens Desigo CC

From Cybersecurity and Infrastructure Security Agency ↗

OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.

The following versions of Siemens Desigo CC are affected:

Desigo CC family V7 vers:all/* (CVE-2025-15467)

Desigo CC family V8 vers:all/* (CVE-2025-15467)

Desigo CC family V9 vers:intdot/