{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Disclosure is not limited. (TLPv2: TLP:CLEAR)",
      "tlp": {
        "label": "WHITE"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances. Successful exploitation could lead to compromise of the client operating system and potential lateral movement within the organization.",
        "title": "Summary"
      },
      {
        "category": "general",
        "text": "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity",
        "title": "General Recommendations"
      },
      {
        "category": "general",
        "text": "For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories",
        "title": "Additional Resources"
      },
      {
        "category": "legal_disclaimer",
        "text": "The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "productcert@siemens.com",
      "name": "Siemens ProductCERT",
      "namespace": "https://www.siemens.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family - HTML Version",
        "url": "https://cert-portal.siemens.com/productcert/html/ssa-330084.html"
      },
      {
        "category": "self",
        "summary": "SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family - CSAF Version",
        "url": "https://cert-portal.siemens.com/productcert/csaf/ssa-330084.json"
      }
    ],
    "title": "SSA-330084: Client Code Execution Vulnerability in Desigo CC Product Family",
    "tracking": {
      "current_release_date": "2026-09-08T00:00:00.000Z",
      "generator": {
        "engine": {
          "name": "Siemens ProductCERT CSAF Generator",
          "version": "1"
        }
      },
      "id": "SSA-330084",
      "initial_release_date": "2026-09-08T00:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-09-08T00:00:00.000Z",
          "legacy_version": "1.0",
          "number": "1",
          "summary": "Publication Date"
        }
      ],
      "status": "interim",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "vers:all/*",
                "product": {
                  "name": "Desigo CC ClickOnce Client V6",
                  "product_id": "1"
                }
              }
            ],
            "category": "product_name",
            "name": "Desigo CC ClickOnce Client V6"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "vers:all/*",
                "product": {
                  "name": "Desigo CC ClickOnce Client V7",
                  "product_id": "2"
                }
              }
            ],
            "category": "product_name",
            "name": "Desigo CC ClickOnce Client V7"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "vers:all/*",
                "product": {
                  "name": "Desigo CC family V8",
                  "product_id": "3"
                }
              }
            ],
            "category": "product_name",
            "name": "Desigo CC family V8"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "vers:all/*",
                "product": {
                  "name": "Desigo CC family V9",
                  "product_id": "4"
                }
              }
            ],
            "category": "product_name",
            "name": "Desigo CC family V9"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "vers:all/*",
                "product": {
                  "name": "Desigo CC Flex Client V6",
                  "product_id": "5"
                }
              }
            ],
            "category": "product_name",
            "name": "Desigo CC Flex Client V6"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "vers:all/*",
                "product": {
                  "name": "Desigo CC Flex Client V7",
                  "product_id": "6"
                }
              }
            ],
            "category": "product_name",
            "name": "Desigo CC Flex Client V7"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "vers:all/*",
                "product": {
                  "name": "Desigo CC Installed Client V6",
                  "product_id": "7"
                }
              }
            ],
            "category": "product_name",
            "name": "Desigo CC Installed Client V6"
          },
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "vers:all/*",
                "product": {
                  "name": "Desigo CC Installed Client V7",
                  "product_id": "8"
                }
              }
            ],
            "category": "product_name",
            "name": "Desigo CC Installed Client V7"
          }
        ],
        "category": "vendor",
        "name": "Siemens"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-34223",
      "cwe": {
        "id": "CWE-94",
        "name": "Improper Control of Generation of Code ('Code Injection')"
      },
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "6",
            "4",
            "3",
            "5"
          ]
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents.  Specifically, when the script within a graphics document is designed or modified by an attacker to include malicious commands.  When a user opens a compromised graphics document, the embedded script is executed on the client application instance, allowing an attacker to write arbitrary files to the client's operating system. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it.  This could lead to compromise of the client operating system and potential lateral movement within the organization.",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "1",
          "2",
          "7",
          "8"
        ],
        "known_not_affected": [
          "3",
          "4",
          "5",
          "6"
        ]
      },
      "remediations": [
        {
          "category": "mitigation",
          "details": "Evaluate authorization policy for Graphics application following Least Privilege principle, so only required users have access to the configuration.",
          "product_ids": [
            "1",
            "2",
            "7",
            "8"
          ]
        },
        {
          "category": "none_available",
          "details": "Currently no fix is available",
          "product_ids": [
            "1",
            "2",
            "7",
            "8"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "1",
            "2",
            "7",
            "8"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "The vulnerability has been fixed in this version",
          "product_ids": [
            "4",
            "3"
          ]
        },
        {
          "category": "impact",
          "details": "The vulnerability does not exist in this version",
          "product_ids": [
            "6",
            "5"
          ]
        }
      ],
      "title": "CVE-2026-34223"
    }
  ]
}