CVE-2025-47809: Siemens Desigo Cc Family v5.0

High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.

Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer.

Affected products

  • Siemens Desigo Cc Family v5.0: any version
  • Siemens Desigo Cc Family v5.1: any version
  • Siemens Desigo Cc Family v6: any version
  • Siemens Desigo Cc Family v7: any version
  • Siemens Desigo Cc Family v8: before V8.0 QU2 (fixed in V8.0 QU2)
  • Siemens Sentron Powermanager v5: any version
  • Siemens Sentron Powermanager v6: any version
  • Siemens Sentron Powermanager v7: any version
  • Siemens Sentron Powermanager v8: before V8.0 QU2 (fixed in V8.0 QU2)
  • Siemens SIMATIC Pdm Maintenance Station v5.0: before V5.0 SP2 (fixed in V5.0 SP2)
  • Siemens SIMATIC Wincc Oa v3.18: before V3.18 P032 (fixed in V3.18 P032)
  • Siemens SIMATIC Wincc Oa v3.19: before V3.19 P020 (fixed in V3.19 P020)
  • Siemens SIMATIC Wincc Oa v3.20: before V3.20 P008 (fixed in V3.20 P008)
  • Wibu Codemeter: before 8.30a (fixed in 8.30a)

Published 2025-05-16. Last modified 2026-09-08.