Siemens Desigo DXR and PXC Controllers Vulnerable to BACnet Packet DoS

Answer Brief

A medium-severity denial-of-service vulnerability (CVE-2026-59693) in Siemens Desigo DXR and PXC controllers allows attackers to disrupt building automation systems via malformed BACnet packets, requiring device reset for recovery. Siemens has released patched versions and recommends network segmentation and VPN use for mitigation.

Signal Timeline

A quick visual path for analysts before reading the full brief.

Timeline
  1. 1

    Initial release of Siemens SSA-781903 advisory

  2. 2

    CISA republication as ICSA-26-225-08

  3. 3

    Source fetched and processed

Executive Summary: A medium-severity denial-of-service vulnerability (CVE-2026-59693) in Siemens Desigo DXR and PXC controllers allows attackers to disrupt building automation systems via malformed BACnet packets, requiring device reset for recovery. Siemens has released patched versions and recommends network segmentation and VPN use for mitigation.

Why It Matters

The vulnerability in Siemens Desigo DXR and PXC controllers (CVE-2026-59693) represents a notable security signal in operational technology environments due to its potential to disrupt building automation and control systems via a simple network-based attack. The flaw stems from improper validation of incoming BACnet packets, allowing an unauthenticated attacker on the same network segment to trigger a denial-of-service condition by sending malformed data. This causes the controller to cease responding to legitimate BACnet queries, effectively disrupting HVAC, lighting, access control, or other integrated building management functions until a physical reset or reboot is performed. While the CVSS v3.1 base score of 4.3 rates the severity as MEDIUM, the impact on availability in critical infrastructure settings—such as hospitals, data centers, or transportation hubs—can be operationally significant despite the lack of confidentiality or integrity impact. The attack requires only adjacent network access, meaning an attacker must be on the same local or routed network segment as the target device. This limits remote exploitation unless networks are improperly segmented or exposed via insecure remote access methods. However, the widespread deployment of these controllers across global commercial facilities, critical manufacturing, energy, healthcare, and transportation sectors increases the potential attack surface, especially in environments where OT networks converge with IT or lack proper zoning. Siemens has responded by releasing updated firmware versions: V01.21.233.16-7862 or later for Desigo DXR2, and V02.21.194.36-2715 or later for all affected PXC models. The vendor emphasizes that updating to these versions is the primary remediation path. Additionally, Siemens and CISA reinforce defensive best practices, including network isolation, firewall segmentation, avoidance of direct internet exposure, and use of updated, secure VPNs for any necessary remote access—recognizing that VPN security depends on the integrity of connected endpoints. From an operational perspective, this vulnerability underscores the importance of asset visibility and patch management in OT environments. Unlike IT systems, building automation controllers often operate for years without firmware updates, creating latent exposure to known flaws. Organizations should verify inventory of Desigo DXR and PXC devices, confirm current firmware versions, and prioritize updates where feasible. Where patching is delayed, compensating controls such as network monitoring for anomalous BACnet traffic and strict access controls become critical. The advisory also highlights the value of coordinated disclosure, with credit given to Thomas EBI of Sauter for reporting the issue through Siemens’ ProductCERT channel. The use of CSAF format and CISA’s republication via ICS advisories improves visibility and facilitates faster awareness across asset owners and security teams. While no evidence of active exploitation was cited in the advisory, the simplicity of the attack vector warrants proactive monitoring, particularly in environments where BACnet is used extensively. Looking ahead, security teams should watch for any signs of weaponization or inclusion of this flaw in OT-focused exploit frameworks. Additionally, organizations should assess whether similar improper input validation issues exist in other BACnet-enabled devices across their infrastructure, as the root cause—failure to handle exceptional conditions—may be present in related products. Continuous monitoring of vendor advisories from Siemens ProductCERT and CISA’s ICS webpage is recommended for timely detection of future updates or related vulnerabilities in building automation and control systems.

Event Type: security
Importance: high

Affected Companies

  • Siemens

Affected Sectors

  • Commercial Facilities
  • Critical Manufacturing
  • Energy
  • Healthcare and Public Health
  • Transportation Systems

Key Numbers

  • CVSS v3.1 Base Score: 4.3
  • CVSS Severity: MEDIUM
  • Attack Vector: Adjacent Network (AV:A)
  • Attack Complexity: Low (AC:L)
  • Privileges Required: None (PR:N)
  • User Interaction: None (UI:N)
  • Impact: Availability: Low (A:L)

Timeline

  1. Initial release of Siemens SSA-781903 advisory
  2. CISA republication as ICSA-26-225-08
  3. Source fetched and processed

Frequently Asked Questions

What is the vulnerability in Siemens Desigo DXR and PXC controllers?

CVE-2026-59693 is a denial-of-service vulnerability caused by improper handling of malformed BACnet packets. An attacker can send specially crafted packets to adjacent network devices, causing them to stop responding to BACnet queries until manually reset or rebooted.

Which Siemens products are affected by CVE-2026-59693?

Affected products include Desigo DXR2 versions prior to V01.21.233.16-7862, and Desigo PXC3, PXC4, PXC5.E003, PXC5.E24, and PXC7 versions prior to V02.21.194.36-2715. All listed versions are vulnerable to the BACnet packet DoS flaw.

How can organizations mitigate the risk from this vulnerability?

Siemens and CISA recommend updating to patched firmware (V01.21.233.16-7862 or later for DXR2; V02.21.194.36-2715 or later for PXC series), minimizing network exposure, placing devices behind firewalls, isolating them from business networks, and using updated VPNs for remote access when required.

Is internet exposure a risk factor for this vulnerability?

Yes. Since the attack vector is adjacent network (AV:A), devices accessible from untrusted networks—including the internet—are at risk. CISA advises ensuring control systems are not directly accessible from the internet and are segmented behind firewalls.

What recovery action is needed if a device is exploited via this vulnerability?

Recovery requires a manual device reset or reboot to restore normal functionality. There is no indication of persistent damage or data loss; the impact is limited to availability disruption of BACnet-based building automation functions.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *