Impact
A vulnerability in Siemens Desigo CC clients allows an attacker to embed malicious commands within a graphics document’s script because the application does not properly validate script content. When a user opens such a compromised document, the embedded script runs in the client application context, granting the attacker the ability to write arbitrary files to the operating system. This weakness is classified as CWE-94 and leads to client code execution (CCE).
Affected Systems
The issue affects all versions of the following Siemens Desigo CC products: ClickOnce Client V6 and V7, Flex Client V6 and V7, Installed Client V6 and V7, and the Desigo CC family V8 and V9. Every installed instance of these clients is potentially vulnerable.
Risk and Exploitability
The CVSS score is 8.6, indicating a high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to craft a malicious graphics document and convince a user with sufficient privileges to open it. Successful execution can compromise the client machine and enable lateral movement within the organization.
OpenCVE Enrichment