Security/ siemens · desigo-cc · industrial-control-systems · vulnerability

Siemens Desigo CC Flaw Lets Rigged Graphics Files Run Code

A high-severity bug in Siemens building-automation software lets a booby-trapped graphics document execute code on a user's machine, and there is no patch yet.

A scripting flaw in Siemens' Desigo CC building-management platform can let a malicious graphics file run code on whoever opens it.

The vulnerability, tracked as CVE-2026-34223, lives in how Desigo CC handles user-defined graphics documents that carry embedded scripts. Feed it a document rigged with malicious commands, get someone with the right privileges to open it, and the client application executes that script - writing arbitrary files to the operating system underneath. It affects both the V6 and V7 branches of the Desigo CC family. Siemens and CISA rate it 8.2 out of 10, and Siemens has no fix ready; the only advice for now is to lock down who can access the Graphics application at all.

Desigo CC runs building automation - HVAC, access control, the physical plant - inside critical manufacturing and commercial facilities worldwide. A code-execution bug that starts with something as mundane as opening a graphics file is a reminder that industrial software keeps inheriting the same document-based attack patterns that have dogged office suites for decades, just attached to higher-stakes machines.

The bug was reported by Michelin's internal security team, not found in the wild - for now, that is the good news.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →