Vulnerability in Siemens Desigo CC Client Affects Multiple Versions
CVE-2026-34223

8.6HIGH

What is CVE-2026-34223?

A vulnerability exists in multiple versions of Siemens Desigo CC products, which is susceptible to Client Code Execution due to inadequate input validation in user-defined graphics. Attackers can embed harmful scripts within graphics documents. When a user opens one of these compromised documents, the script is run on their client device, potentially leading to arbitrary file writing on the operating system. For successful exploitation, an attacker must craft a specific malicious document and convince a user with the right privileges to open it, which can allow for broader security breaches across the organization.

Affected Version(s)

Desigo CC ClickOnce Client V6 0

Desigo CC ClickOnce Client V7 0

Desigo CC family V8 0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.