Remote Code Execution Vulnerability in Desigo CC by Siemens
CVE-2024-23815

8.7HIGH

Key Information:

Vendor

Siemens

Status
Vendor
CVE Published:
13 May 2025

What is CVE-2024-23815?

A vulnerability exists in the Desigo CC server application that could allow unauthenticated attackers to execute arbitrary SQL queries on the server database. This issue arises when access from installed clients to the Desigo CC server is permitted from less secure networks, or even within highly protected zones if specific security measures are not adequately enforced. By modifying the client binary, attackers can exploit the system through the event port (default: 4998/tcp), posing a significant risk to the integrity and confidentiality of the server's data.

Affected Version(s)

Desigo CC 0

Desigo CC 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.