Evaluate authorization policy for the Graphics application following the Least Privilege principle, ensuring only required users have access. Minimize network exposure for control system devices; ensure systems are not internet-facing. Locate control system networks behind firewalls and isolate from business networks. Use secure remote access methods such as VPNs, keeping them updated. Follow Siemens operational guidelines for industrial security. Monitor Siemens advisory SSA-330084 for updates on remediation.
Quick answers
What is CVE-2026-34223?
Evaluate authorization policy for the Graphics application following the Least Privilege principle, ensuring only required users have access. Minimize network exposure for control system devices; ensure systems are not internet-facing. Locate control system networks behind firewalls and isolate from business networks. Use secure remote access methods such as VPNs, keeping them updated. Follow Siemens operational guidelines for industrial security. Monitor Siemens advisory SSA-330084 for updates on remediation.
How severe is CVE-2026-34223?
high, CVSS 8.2
Is CVE-2026-34223 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-34223 be mitigated?
Evaluate authorization policy for the Graphics application following the Least Privilege principle, ensuring only required users have access. Minimize network exposure for control system devices; ensure systems are not internet-facing. Locate control system networks behind firewalls and isolate from business networks. Use secure remote access methods such as VPNs, keeping them updated. Follow Siemens operational guidelines for industrial security. Monitor Siemens advisory SSA-330084 for updates on remediation.
CVSS
8.2
Vendor
Siemens
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Desigo CC family V6, Desigo CC family V7
Mitigation
Evaluate authorization policy for the Graphics application following the Least Privilege principle, ensuring only required users have access. Minimize network exposure for control system devices; ensure systems are not internet-facing. Locate control system networks behind firewalls and isolate from business networks. Use secure remote access methods such as VPNs, keeping them updated. Follow Siemens operational guidelines for industrial security. Monitor Siemens advisory SSA-330084 for updates on remediation.
A Client Code Execution (CCE) vulnerability has been identified in Siemens Desigo CC family products V6 and V7. The flaw stems from insufficient input validation when handling scripts embedded within user-defined graphics documents. Successful exploitation could allow an attacker to execute arbitrary code on client devices, write arbitrary files to the operating system, and facilitate lateral movement within the organization. The vulnerability carries a CVSS 3.1 base score of 8.2 (HIGH) and has been assigned CVE-2026-34223. No patch is currently available; mitigation focuses on authorization policy review and network exposure reduction.