CVE-2026-34223
Siemens ProductCERT Advisory SSA-330084
Beschreibung
Eine Schwachstelle wurde in Desigo CC ClickOnce Client V6 (alle Versionen), Desigo CC ClickOnce Client V7 (alle Versionen), Desigo CC Familie V8 (alle Versionen), Desigo CC Familie V9 (alle Versionen), Desigo CC Flex Client V6 (alle Versionen), Desigo CC Flex Client V7 (alle Versionen), Desigo CC Installierter Client V6 (alle Versionen) und Desigo CC Installierter Client V7 (alle Versionen) identifiziert. Die betroffene Anwendung ist anfällig für die Ausführung von Clientcode (CCE) aufgrund unzureichender Eingabeverifikation beim Umgang mit in benutzerdefinierten Grafikdokumenten eingebetteten Skripten. Insbesondere, wenn das Skript innerhalb eines Grafikdokuments so gestaltet oder von einem Angreifer modifiziert wird, dass es bösartige Befehle enthält. Wenn ein Benutzer ein kompromittiertes Grafikdokument öffnet, wird das eingebettete Skript in der Instanz der Clientanwendung ausgeführt und ermöglicht einem Angreifer, willkürliche Dateien im Betriebssystem des Clients zu schreiben. Eine erfolgreiche Ausnutzung erfordert es, dass ein Angreifer ein bösartiges Grafikdokument erstellt und einen Benutzer mit ausreichenden Berechtigungen dazu verleitet, es anzuzeigen. Dies könnte zur Kompromittierung des Clientbetriebssystems führen und potenzielle horizontale Bewegung innerhalb der Organisation ermöglichen.
Metriken
Alle Metriken anzeigen
Weakness-Klassen (CWE)
CWE-94Base
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
cwe.mitre.org →
Quellen & Referenzen
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-09-14 14:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-34223","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-09-08 09:18 UTC· productcert@siemens.com
- Description: A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All versions), Desigo CC Installed Client V7 (All versions). The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, when the script within a graphics document is designed or modified by an attacker to include malicious commands. When a user opens a compromised graphics document, the embedded script is executed on the client application instance, allowing an attacker to write arbitrary files to the client's operating system. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it. This could lead to compromise of the client operating system and potential lateral movement within the organization.
- CVSS V4.0: AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CVSS V3.1: AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- CWE: CWE-94