Executive brief
Siemens Desigo CC is a building management and automation platform used to control critical infrastructure like HVAC, lighting, and security systems in commercial facilities and manufacturing plants. A code injection vulnerability allows attackers to execute arbitrary code on client workstations through malicious graphics documents, potentially compromising the operating system and enabling lateral movement across the organization's network.
Technical details
The vulnerability is a code injection flaw (CWE-94) in the Desigo CC graphics document handler that fails to properly validate or sanitize embedded scripts. When a user with appropriate privileges opens a specially crafted graphics document containing malicious scripts, the embedded code is executed in the context of the client application, allowing write access to the client operating system. The attack requires local access (AV:L) and user interaction (UI:R) to open the malicious document, but can produce high impact across confidentiality, integrity, and availability. No patch is currently available; mitigation involves restricting Graphics application access through authorization policies following the principle of least privilege.
Affected products
- Siemens Desigo CC family V6 all versions
- Siemens Desigo CC family V7 all versions
Timeline
- 2026-09-08: disclosed: Initial release by Siemens ProductCERT
- 2026-09-22: advisory: CISA republication as ICSA-26-265-05