Siemens Desigo CC
Act NowCVSS 9.8ICS-CERT ICSA-26-209-01Jul 14, 2026
Siemens
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
OpenSSL contains a stack-based buffer overflow vulnerability (CWE-787) in the Desigo CC building management system. A remote attacker can exploit this without authentication to cause a denial of service by crashing the system or potentially execute arbitrary commands. The vulnerability affects all versions of Desigo CC V7, V8, and V9 prior to V9.0.1.
What this means
What could happen
An attacker can remotely crash the Desigo CC building management system, causing loss of HVAC and facility controls, or potentially execute code to manipulate building operations like temperature setpoints, access controls, or alarm systems.
Who's at risk
Building management operators and facility engineers managing Siemens Desigo CC systems for HVAC control, lighting management, and access control in municipal and commercial buildings. This affects all versions of V7, V8, and early V9 installations.
How it could be exploited
The attacker sends a crafted network request to the Desigo CC system that triggers a stack buffer overflow in the embedded OpenSSL library. No authentication is required. Successful exploitation could allow the attacker to execute arbitrary commands on the building management platform or crash it, disrupting facility controls.
Prerequisites
- Network access to the Desigo CC system on its listening port (typically port 80/443)
- No credentials or user interaction required
Remotely exploitableNo authentication requiredLow complexityHigh EPSS score (47.6%)No patch available for V7Affects building safety systems
Exploitability
Likely to be exploited — EPSS score 48.2%
Public Proof-of-Concept (PoC) on GitHub (5 repositories)
Affected products (3)
2 with fix1 EOL
ProductAffected VersionsFix Status
Desigo CC family V8All versionsFix available
Desigo CC family V7All versionsNo fix (EOL)
Remediation & Mitigation
0/4
Do now
0/1HARDENINGFor Desigo CC V7 systems where no patch is available, restrict network access to the system by implementing firewall rules to block inbound traffic from untrusted networks
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXUpdate Desigo CC V9 systems to version 9.0 QU1 or later
HOTFIXUpdate Desigo CC V8 systems to patch V8.0 QU2.0021 or later
Mitigations - no patch available
0/1Desigo CC family V7 has reached End of Life. The vendor will not release a patch. Apply the following compensating controls:
HARDENINGIsolate Desigo CC systems on a dedicated facility management network segment, limiting access from general IT networks
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/a8e7476a-6798-40e6-b069-5cf32554cccdGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.