CVE-2026-34223 Details
Description
A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All versions), Desigo CC Installed Client V7 (All versions). The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, when the script within a graphics document is designed or modified by an attacker to include malicious commands. When a user opens a compromised graphics document, the embedded script is executed on the client application instance, allowing an attacker to write arbitrary files to the client's operating system. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it. This could lead to compromise of the client operating system and potential lateral movement within the organization.
A client code execution vulnerability has been identified in various Desigo CC applications, including ClickOnce, Flex, and Installed Clients, all versions. The vulnerability arises from inadequate input validation of scripts embedded in user-defined graphics documents. An attacker can exploit this by crafting a malicious graphics document that, when opened by a user with sufficient privileges, executes the embedded script on the client application. This exploitation allows the attacker to write arbitrary files to the client's operating system, potentially compromising it and facilitating lateral movement within the organization.
Siemens recommends evaluating the authorization policy for the Graphics application based on the Least Privilege principle, ensuring that only necessary users have access to the configuration. For general security, it is advised to protect network access to devices with appropriate measures and to follow Siemens' operational guidelines for Industrial Security.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-330084.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Siemens Desigo CC ClickOnce Client | <= 6 <= 7 |
CPE
Remediation
| |
| Siemens Desigo CC | <= 8 <= 9 |
CPE
Remediation
| |
| Siemens Desigo CC Flex Client | <= 6 <= 7 |
CPE
Remediation
| |
| Siemens Desigo CC Installed Client | <= 6 <= 7 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion