← Back to Feed
Siemens Desigo CC
CVE-2025-15467
July 28, 2026 · CISA (US-CERT) · Severity: CRITICAL
A critical stack buffer overflow vulnerability in OpenSSL's CMS parsing (CVE-2025-15467) affects Siemens Desigo CC building automation systems. An attacker can trigger remote code execution or denial of service by sending a crafted CMS message. Siemens recommends updating affected Desigo CC versions to V9.0.1 or later.
Key Takeaways
- Stack buffer overflow in OpenSSL's CMS parsing allows remote code execution or denial of service.
- Siemens Desigo CC versions V7, V8, and V9 before 9.0.1 are affected by this critical vulnerability.
- Update to latest firmware versions or apply recommended countermeasures to mitigate the risk.