A malformed CMS message can make Desigo CC crash before OpenSSL checks whether the content is valid. That means the bug sits in the parser itself, not in a trust check after the fact, and a bad message is enough to hit the stack overflow without any valid key material.
CISA and Siemens say CVE-2025-15467 affects Desigo CC family V7, V8, and V9 below 9.0.1. Siemens has a fix for V9.0 QU1 or later and V8.0 QU2.0021, but V7 is still on interim mitigations, so the remediation path is not uniform across affected deployments.