As cited
Copy frozen at (site build).
vulnerabilities
Siemens Desigo CC
OpenSSL published a stack-based buffer overflow vulnerability (CVE-2025-15467) affecting Siemens Desigo CC building management systems, with a CVSS score of 9.8. Remote attackers can send crafted CMS messages to trigger denial of service or potentially execute code without authentication. Siemens has released patches for Desigo CC V9 (version 9.0.1 and later) and V8 (patch V8.0 QU2.0021), with V7 having no fix currently available.
Why it matters: Critical infrastructure operators worldwide using Desigo CC for building and energy management face immediate remote code execution risk from unauthenticated network attacks; patching to the latest versions should be prioritized immediately.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Siemens Desigo CC
OpenSSL published a stack-based buffer overflow vulnerability (CVE-2025-15467) affecting Siemens Desigo CC building management systems, with a CVSS score of 9.8. Remote attackers can send crafted CMS messages to trigger denial of service or potentially execute code without authentication. Siemens has released patches for Desigo CC V9 (version 9.0.1 and later) and V8 (patch V8.0 QU2.0021), with V7 having no fix currently available.
Why it matters: Critical infrastructure operators worldwide using Desigo CC for building and energy management face immediate remote code execution risk from unauthenticated network attacks; patching to the latest versions should be prioritized immediately.
- Source published
- First seen by Cybersecurity Tracker