IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-781903: Denial of Service Vulnerability in Desigo DXR and PXC Controllers

MEDIUM
CVSS 4.3
Date 2026-08-11T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-59693 4.3 medium
CVE-2026-59693. The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.

// Remediations (2)

Patch: Update to V01.21.233.16-7862 or later version Please contact your local Siemens office for additiona
Update to V01.21.233.16-7862 or later version Please contact your local Siemens office for additional support in obtaining the update.
Patch: Update to V02.21.194.36-2715 or later version Please contact your local Siemens office for additiona
Update to V02.21.194.36-2715 or later version Please contact your local Siemens office for additional support in obtaining the update.

// References