Siemens Desigo: pacchetti BACnet malformati possono causare un DoS sui controller
Vulnerabilities

Illustrative image generated with AI

Siemens Desigo: malformed BACnet packets can cause DoS on controllers

CVE-2026-59693: Siemens Desigo controllers vulnerable to DoS via malformed BACnet packets. Learn about affected products, attack details, and fixes.

Text generated by artificial intelligence, published without human review. AI transparency

Vulnerability affects six controller families

On August 13, 2026, Siemens disclosed CVE-2026-59693, classified as CWE-754 for improper handling of unusual or exceptional conditions.

The issue affects the following products:

  • Desigo DXR2: versions prior to V01.21.233.16-7862
  • Desigo PXC3: versions prior to V01.21.233.16-7862
  • Desigo PXC4: versions prior to V02.21.194.36-2715
  • Desigo PXC5.E003: versions prior to V02.21.194.36-2715
  • Desigo PXC5.E24: versions prior to V02.21.194.36-2715
  • Desigo PXC7: versions prior to V02.21.194.36-2715

The vulnerability was reported to Siemens by Thomas EBI of Sauter.

How the attack works

An attacker can send malformed BACnet packets to a controller. Processing the malformed input may cause the device to stop responding to BACnet requests.

This results in a denial-of-service condition. Restoring normal operation requires a device reset or reboot.

The attack requires access to the adjacent network, but no privileges or user interaction. Its complexity is low. The CVSS 3.1 vector is:

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

The score is 4.3, with Medium severity. The reported impact is limited to availability, with no stated effect on data confidentiality or integrity.

Potential impact

Desigo controllers are used in commercial facilities, critical manufacturing, energy infrastructure, healthcare and public health, as well as transportation systems.

A disruption of BACnet communications could therefore affect the monitoring or control of connected systems until the device is manually restored. The affected devices are deployed worldwide.

Updates and mitigation measures

Siemens recommends updating the controllers to the latest available versions, or at least to the versions listed above as the fixed baseline for each product family. Before performing the update, operators should assess the impact of the reboot and any associated operational risks.

Organizations should also:

  • prevent direct Internet access to the devices;
  • segment OT networks and remote systems from corporate networks using firewalls;
  • use VPNs for remote access;
  • keep controllers, connected equipment and VPN systems up to date;
  • follow Siemens industrial security guidelines and the recommendations in the product manuals;
  • review logs for malformed BACnet packets or unexpected interruptions in BACnet responses.

For assistance with Siemens product vulnerabilities, contact Siemens ProductCERT.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Related topicsSiemens DesigoBACnetCVE-2026-59693denial of serviceDoScybersecurity vulnerabilityindustrial control systemsOT security
Back to home