Client Code Execution Vulnerability in Desigo CC Product Family

Plan PatchCVSS 8.2SSA-330084Sep 8, 2026
Siemens
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

A vulnerability in Desigo CC allows arbitrary code execution through malicious graphics documents containing embedded scripts. When a user opens a specially crafted graphics document in the Desigo CC client application, the embedded scripts execute on the client workstation. This affects all versions of Desigo CC ClickOnce Client and Installed Client V6 and V7. The vendor has not released a patch; only mitigation through access controls is available.

What this means
What could happen
An attacker could execute arbitrary code on a client workstation running Desigo CC by crafting a malicious graphics document, potentially compromising the operating system and providing a foothold for lateral movement into your building automation and controls network.
Who's at risk
Building automation and controls system operators and engineers who use Desigo CC to manage HVAC, lighting, energy management, and other facility systems. This affects any organization using Siemens Desigo CC for building management, particularly those where client workstations are connected to the same network as operational control systems.
How it could be exploited
An attacker creates a malicious graphics document containing embedded scripts and delivers it to a user with access to Desigo CC (e.g., via email or a compromised repository). When the user opens the graphics document in Desigo CC, the embedded script executes on the client workstation with the privileges of the logged-in user. From there, the attacker can pivot to other systems on the network.
Prerequisites
  • User must have access to Desigo CC graphics application
  • User must open a specially crafted graphics document from the attacker
  • No patch is available; mitigation-only status indicates this is a design limitation
local code executionuser interaction requiredno vendor patch availableprivileged user access required but user has legitimate rolelateral movement risk to OT network
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (4)
4 pending
ProductAffected VersionsFix Status
Desigo CC ClickOnce Client V6All versionsNo fix yet
Desigo CC ClickOnce Client V7All versionsNo fix yet
Desigo CC Installed Client V6All versionsNo fix yet
Desigo CC Installed Client V7All versionsNo fix yet
Remediation & Mitigation
0/3
Do now
0/2
HARDENINGRestrict Graphics application access in Desigo CC to only personnel who require it for configuration duties, using authorization policies and role-based access controls
HARDENINGTrain users to avoid opening graphics documents from untrusted sources or unexpected communications
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate Desigo CC client workstations from critical process control networks and from each other where feasible
API: /api/v1/advisories/87b1e0e3-d6d9-4982-81a0-0cc5d70b8f10

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Client Code Execution Vulnerability in Desigo CC Product Family | CVSS 8.2 - OTPulse