Junglewise Threat Intelligence

CVE-2026-59693: Siemens Desigo DXR and PXC DoS via malformed BACnet packet

CVE-2026-59693 · Severity: medium · CVSS 4.3 · Published 2026-08-11

Vendors: Siemens.

Executive brief

Siemens Desigo DXR and PXC controllers are building automation devices used to manage HVAC, lighting, and other facilities infrastructure. An attacker on the adjacent network can send a malformed BACnet packet to crash the device, causing it to stop responding and disrupting building operations until manually rebooted. This affects multiple product lines and requires network proximity to exploit.

Technical details

A denial-of-service vulnerability (CWE-754: Improper Check for Unusual or Exceptional Conditions) exists in the BACnet protocol processing logic of Desigo DXR and PXC controllers. An attacker with adjacent network access can send a specially crafted BACnet packet that causes the device to crash and become unresponsive to legitimate BACnet queries. Recovery requires a manual device reset or reboot. Patches are available for all affected product lines; users should update to V01.21.233.16-7862 (DXR2/PXC3) or V02.21.194.36-2715 (PXC4/PXC5/PXC7).

Affected products

  • Siemens Desigo DXR2 All versions < V01.21.233.16-7862
  • Siemens Desigo PXC3 All versions < V01.21.233.16-7862
  • Siemens Desigo PXC4 All versions < V02.21.194.36-2715
  • Siemens Desigo PXC5.E003 All versions < V02.21.194.36-2715
  • Siemens Desigo PXC5.E24 All versions < V02.21.194.36-2715
  • Siemens Desigo PXC7 All versions < V02.21.194.36-2715

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched: Patch versions released: V01.21.233.16-7862 and V02.21.194.36-2715

References