← Back to Feed

Siemens Desigo CC

CVE-2025-15467

July 28, 2026 · CISA (US-CERT) · Severity: CRITICAL

A critical stack buffer overflow vulnerability in OpenSSL's CMS parsing (CVE-2025-15467) affects Siemens Desigo CC building automation systems. An attacker can trigger remote code execution or denial of service by sending a crafted CMS message. Siemens recommends updating affected Desigo CC versions to V9.0.1 or later.

Key Takeaways

  • Stack buffer overflow in OpenSSL's CMS parsing allows remote code execution or denial of service.
  • Siemens Desigo CC versions V7, V8, and V9 before 9.0.1 are affected by this critical vulnerability.
  • Update to latest firmware versions or apply recommended countermeasures to mitigate the risk.
☕ Buy a Coffee