Skip to content
Threat Feed
low advisory

Denial of Service Vulnerability in Siemens Desigo DXR and PXC Controllers

Siemens Desigo DXR and PXC controllers are vulnerable to a denial-of-service condition (CVE-2026-59693) triggered by malformed BACnet packets, requiring a manual device reboot.

CVE search metadata

CVE search record: CVE-2026-59693. Severity: medium. CVSS: 4.3. EPSS: 0.16%. KEV: no. Product: Desigo DXR2, Desigo PXC3, Desigo PXC4, Desigo PXC5.E003, Desigo PXC5.E24, Desigo PXC7. Brief: Denial of Service Vulnerability in Siemens Desigo DXR and PXC Controllers. Brief link: https://feed.craftedsignal.io/briefs/2026-08-siemens-desigo-dos/

Siemens has disclosed a security vulnerability affecting various models of its Desigo DXR and PXC building automation controllers. The vulnerability, tracked as CVE-2026-59693, stems from an improper check for unusual or exceptional conditions within the device's BACnet protocol implementation. An unauthenticated attacker with network access to the controller can send a specifically crafted, malformed BACnet packet that causes the device to cease responding to legitimate network queries. This results in a denial-of-service (DoS) condition, impacting building management functions. Restoration of services requires a manual hardware reset or power cycle of the affected device. Siemens has released firmware updates for the impacted product lines and strongly recommends that operators transition to the patched versions to eliminate the risk. The vulnerability is rated with a CVSS 3.1 base score of 4.3 (Medium), reflecting the requirement for adjacent network access and the need for manual intervention to recover.

Impact

The vulnerability affects critical infrastructure sectors including energy, healthcare, public health, commercial facilities, and manufacturing. Successful exploitation leads to a loss of availability for the targeted Desigo controllers, potentially disrupting facility environmental and automation controls. Because these devices are typically managed via local industrial networks, the impact is primarily felt by organizations operating in the physical security and facility management domains. There is no evidence of remote code execution or data exfiltration associated with this vulnerability.

Recommendation

Prioritize patching of all identified Desigo DXR and PXC controllers listed in the affected products section. Given the requirement for manual intervention to restore service, operators should conduct a risk assessment before deployment to account for potential downtime during the maintenance cycle. Implement strict network segmentation to restrict BACnet traffic to authorized devices only and ensure controllers are not accessible from the public internet. Monitor industrial networks for anomalous BACnet traffic patterns that deviate from standard operational baselines.


Immediate actions

Patch affected Siemens Desigo controllers to the latest firmware versions

IT Operations 7d

Mitigations

Restrict BACnet protocol traffic via network firewalls and ensure devices are isolated from non-industrial networks

immediate IT Operations

CVE-2026-59693