Full Report
A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Analysis Summary
# Vulnerability: Denial of Service in Siemens Desigo DXR and PXC Controllers
## CVE Details
- **CVE ID:** CVE-2026-59693
- **CVSS Score:**
- CVSS v4.0: 5.3 (Medium)
- CVSS v3.1: 4.3 (Medium)
- **CWE:** CWE-754: Improper Check for Unusual or Exceptional Conditions
## Affected Systems
- **Products:**
- Desigo DXR2
- Desigo PXC3
- Desigo PXC4
- Desigo PXC5 (E003 and E24)
- Desigo PXC7
- **Versions:**
- DXR2 and PXC3: All versions < V01.21.233.16-7862
- PXC4, PXC5, and PXC7: All versions < V02.21.194.36-2715
- **Configurations:** Devices utilizing the BACnet protocol for communication.
## Vulnerability Description
Affected Siemens Desigo controllers contain a flaw in how they handle incoming BACnet traffic. Specifically, the software fails to properly validate or handle malformed BACnet packets. An attacker can exploit this by sending a specifically crafted packet to the device, causing the BACnet service to hang or stop responding to queries. The device does not automatically recover; a physical or manual reset/reboot is required to restore functionality.
## Exploitation
- **Status:** Not exploited (Reported via coordinated disclosure).
- **Complexity:** Low
- **Attack Vector:** Adjacent (Requires access to the local or building automation network).
## Impact
- **Confidentiality:** None
- **Integrity:** None
- **Availability:** Low (System becomes unresponsive to BACnet queries, requiring manual intervention).
## Remediation
### Patches
Siemens recommends updating to the following versions or later:
- **Desigo DXR2 / PXC3:** Update to V01.21.233.16-7862
- **Desigo PXC4 / PXC5 / PXC7:** Update to V02.21.194.36-2715
*Note: Users should contact their local Siemens office for assistance in obtaining these updates.*
### Workarounds
- **Network Segmentation:** Protect network access to the devices with firewalls or VLANs to ensure only authorized traffic reaches the BACnet interface.
- **Operational Guidelines:** Adhere to Siemens’ operational guidelines for Industrial Security and ensure devices are operated within a protected IT/OT environment.
## Detection
- **Indicators of Compromise:** Controller stops responding to standard BACnet management station queries or building automation software commands.
- **Detection Methods:** Monitor network traffic for malformed BACnet packets or unusual protocol behavior originating from unauthorized adjacent hosts.
## References
- **Vendor Advisory:** hxxps://cert-portal.siemens[.]com/productcert/html/ssa-781903.html
- **Siemens Industrial Security:** hxxps://www.siemens[.]com/industrialsecurity
- **Operational Guidelines:** hxxps://www.siemens[.]com/cert/operational-guidelines-industrial-security