Security & Threat Intelligence · 28.07.2026, 19:03 UTC
Siemens Desigo CC
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA ICS Advisories ↗ |
| Veröffentlicht | 28.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2025-15467. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions of Siemens Desigo CC are affected:
Desigo CC family V7 vers:all/* (CVE-2025-15467) Desigo CC family V8 vers:all/* (CVE-2025-15467) Desigo CC family V9 vers:intdot/<9.0.1 (CVE-2025-15467)
CVSS Vendor Equipment Vulnerabilities
v3 9.8 Siemens Siemens Desigo CC Out-of-bounds Write
Background
Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2025-15467
Issue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. …
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- info USN-8653-1: PostgreSQL vulnerabilities
- high ZDI-26-577: Trend Micro VPN OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
- info HoF-Bench: Rediscovering Real AI-Discovered CVEs Without Frontier Models
- info AnyPoC: Universal Proof-of-Concept Test Generation for Scalable LLM-Based Bug Detection