VYPR
advisoryPublished Aug 13, 2026· 1 source

Siemens Desigo Controllers Vulnerable to Denial-of-Service Attacks

Siemens Desigo DXR and PXC controllers are susceptible to denial-of-service vulnerabilities, potentially disrupting critical building automation systems.

Siemens has issued a warning regarding a denial-of-service (DoS) vulnerability affecting its Desigo DXR and PXC series of building automation controllers. The vulnerability, identified as CVE-2026-59693, allows an attacker to render the affected devices unresponsive by sending specially crafted BACnet packets.

The exploitation of this flaw involves sending malformed BACnet packets to the vulnerable controllers. Successful exploitation would cause the devices to cease responding to BACnet queries, effectively halting their normal operation. To restore functionality, a manual device reset or reboot is required, which could lead to significant operational downtime in facilities relying on these systems.

The affected product versions include Desigo DXR2 and PXC3 controllers prior to version V01.21.233.16-7862, and Desigo PXC4, PXC5.E003, PXC5.E24, and PXC7 controllers prior to version V02.21.194.36-2715. These controllers are widely deployed in critical infrastructure sectors such as commercial facilities, critical manufacturing, energy, healthcare, and transportation systems worldwide.

Siemens has addressed the vulnerability by releasing updated versions of the affected software. Users are strongly advised to update their Desigo DXR and PXC controllers to the latest versions, specifically V01.21.233.16-7862 or later for DXR2 and PXC3, and V02.21.194.36-2715 or later for PXC4, PXC5, and PXC7 models. The company recommends contacting local Siemens offices for assistance in obtaining and applying these updates.

The Common Vulnerabilities and Exposures (CVE) system has assigned CVE-2026-59693 to this issue. The vulnerability has a CVSS v3.1 base score of 4.3, categorizing it as medium severity. The attack vector is described as adjacent (AV:A), with low complexity (AC:L), no privileges required (PR:N), no user interaction needed (UI:N), and a low impact on confidentiality, integrity, and availability (C:N/I:N/A:L).

CISA has echoed Siemens' recommendations, urging users to minimize network exposure for all control system devices and ensure they are not accessible from the internet. Isolating control system networks behind firewalls and using secure remote access methods like VPNs are also advised. Organizations should conduct thorough impact and risk assessments before implementing any defensive measures.

This vulnerability, categorized under CWE-754 (Improper Check for Unusual or Exceptional Conditions), highlights the ongoing security challenges within the Industrial Internet of Things (IIoT) and building automation systems. The interconnected nature of these systems means that a single vulnerability can have cascading effects on critical infrastructure operations.

Synthesized by Vypr AI