CISA

Siemens Desigo CC family

From Cybersecurity and Infrastructure Security Agency ↗

A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.

The following versions of Siemens Desigo CC family are affected:

Desigo CC family V6 vers:all/* (CVE-2026-34223)

Desigo CC family V7 vers:all/* (CVE-2026-34223)

Vendor

Equipment

Siemens

Siemens Desigo CC family

Improper Control of Generation of Code ('Code Injection')

Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities

Countries/Areas Deployed: Worldwide

Company Headquarters Location:...