Full Report
OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
Analysis Summary
# Vulnerability: OpenSSL Stack-Based Buffer Overflow in Siemens Desigo CC
## CVE Details
- **CVE ID:** CVE-2025-15467
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-787: Out-of-bounds Write
## Affected Systems
- **Products:** Desigo CC family (including Desigo CC, Desigo CC Compact, Desigo CC Connect, and Cerberus DMS).
- **Versions:**
- Desigo CC V7: All versions.
- Desigo CC V8: All versions prior to patch V8.0 QU2.0021.
- Desigo CC V9: All versions prior to V9.0 QU1.
- **Configurations:** Systems processing untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM).
## Vulnerability Description
A stack-based buffer overflow exists in OpenSSL versions 3.0 through 3.6 when parsing CMS `AuthEnvelopedData` messages. The flaw occurs when processing maliciously crafted AEAD parameters; specifically, an Initialization Vector (IV) encoded in ASN.1 parameters is copied into a fixed-size stack buffer without length validation. Because this out-of-bounds write occurs before authentication or tag verification, an attacker does not need valid key material to trigger the vulnerability.
## Exploitation
- **Status:** Not explicitly stated as exploited in the wild; however, the technical details are public via OpenSSL and Siemens.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Potential for Remote Code Execution)
- **Integrity:** High (Potential for Remote Code Execution)
- **Availability:** High (Denial of Service/System Crash)
## Remediation
### Patches
- **Desigo CC V8:** Update to Patch **V8.0 QU2.0021** or later.
- **Desigo CC V9:** Update to **V9.0 QU1** or later.
- **Desigo CC V7:** No fix is currently available; users should monitor for future updates.
### Workarounds
- **Network Segmentation:** Protect network access with firewalls and VPNs to limit exposure to untrusted CMS/PKCS#7 traffic.
- **Environment Hardening:** Configure the environment according to Siemens operational guidelines for protected IT environments.
- **Redundancy:** For critical power systems, ensure multi-level redundant secondary protection schemes are in place to maintain grid resilience.
## Detection
- **Indicators of Compromise:** Unusual application crashes (DoS) within Desigo CC services or abnormal stack-based memory patterns.
- **Detection methods and tools:**
- Monitor network traffic for malformed CMS/PKCS#7 structures, specifically those containing oversized IV parameters in AEAD ciphers.
- Use vulnerability scanners to identify Siemens Desigo CC installations running vulnerable software versions.
## References
- **Siemens Advisory:** hxxps://cert-portal.siemens[.]com/productcert/html/ssa-734552.html
- **Siemens Support (V8 Patch):** hxxps://support.industry.siemens[.]com/cs/ww/en/view/109989041/
- **Siemens Support (V9 Patch):** hxxps://support.industry.siemens[.]com/cs/ww/en/view/110002555/
- **Siemens Grid Security:** hxxps://www.siemens[.]com/gridsecurity