# Siemens Desigo BACnet Flaw Enables DoS

Published: 2026-08-13 · Severity: routine · Sectors: manufacturing, energy, healthcare, transportation
Canonical: https://vorant.io/reports/bf848e0d-f24f-5a75-af70-f900e4205de1/siemens-desigo-bacnet-flaw-enables-dos

> A malformed BACnet packet can crash Siemens Desigo DXR and PXC building controllers until manually rebooted; Siemens has released fixed firmware.

Siemens disclosed a denial-of-service vulnerability (CVE-2026-59693) affecting its Desigo DXR and PXC building automation controllers, including the DXR2, PXC3, PXC4, PXC5.E003, PXC5.E24, and PXC7 models. The flaw stems from improper handling of exceptional conditions (CWE-754) when the device parses BACnet protocol packets, allowing an attacker with network access to send a malformed BACnet packet that causes the controller to stop responding to BACnet queries. Recovery requires a manual device reset or reboot, meaning exploitation can produce sustained operational disruption to building management systems until an operator intervenes.

These controllers are widely deployed across commercial facilities, critical manufacturing, energy, healthcare, and transportation sectors worldwide, making the availability impact of note for building automation and environmental control systems tied to these industries. Siemens has released updated firmware versions (V01.21.233.16-7862 for DXR2/PXC3 and V02.21.194.36-2715 for PXC4/PXC5/PXC7) that address the issue, and recommends organizations update immediately or contact Siemens for support. The vulnerability was responsibly reported by Thomas Ebi of Sauter, and there is no indication in the advisory of active exploitation in the wild.

CISA republished this as a verbatim conversion of Siemens' own advisory (SSA-781903) and reiterates standard ICS hardening guidance: minimize internet exposure of control systems, isolate them behind firewalls from business networks, and use VPNs with awareness of their own risks when remote access is required.

## Mentioned in this report

- Vulnerabilities: CVE-2026-59693

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-08

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/bf848e0d-f24f-5a75-af70-f900e4205de1/siemens-desigo-bacnet-flaw-enables-dos.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
