ICSA-21-257-17
Desigo CC, Desigo CC Compact and Cerberus DMS that use CCOM communication component hosted in IIS contain a deserialisation vulnerability that could allow an unauthenticated attacker to perform remote code execution. Only those systems that use Windows App and/or IE XBAP Web Client are affected. Regular installed clients and the new HTML5 Flex Clients are not impacted by this vulnerability. Note that the risk of this vulnerability being exploited is particularly high for any Desigo CC system that is connected directly to the Internet. For systems not accessible directly from the Internet, an attacker would need to have access to the local network to exploit this vulnerability. Siemens has released updates for the affected products and recommends to update to the latest versions.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Desigo CC Compact V4.0 | ||
| Desigo CC Compact V5.0 | ||
| Cerberus DMS V4.0 | ||
| Desigo CC V4.0 | ||
| Desigo CC V5.0 | ||
| Cerberus DMS V4.1 | ||
| Cerberus DMS V4.2 | ||
| Cerberus DMS V5.0 | ||
| Desigo CC V4.1 | ||
| Desigo CC Compact V4.2 | ||
| Desigo CC V4.2 | ||
| Desigo CC Compact V4.1 |
Timeline
- Sep 14, 2021 CVE Published
- May 6, 2025 CVE Updated
References
- https://cert-portal.siemens.com/productcert/csaf/ssa-453715.json advisory
- https://cert-portal.siemens.com/productcert/txt/ssa-453715.txt advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-453715.pdf advisory
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2021/icsa-21-257-17.json advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-21-257-17 advisory
- https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 url
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices url
- https://www.cisa.gov/topics/industrial-control-systems url
- https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf url
- https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B url
- https://support.industry.siemens.com/cs/document/109801179/ fix
- https://support.industry.siemens.com/cs/document/109800951/ fix