PatchSiren cyber security CVE debrief
CVE-2026-59693 Siemens CVE debrief
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715). The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.
- Vendor
- Siemens
- Product
- Desigo DXR2
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-08-28
Who should care
Organizations using affected Desigo devices should prioritize patching and implementing compensating controls to mitigate the vulnerability. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess potential exposure, verify device configurations, and ensure that appropriate defensive measures are in place. The vulnerability's impact on business operations and security posture should be carefully evaluated, and affected devices should be remediated as soon as possible to prevent potential exploitation attempts. Additionally, defenders should review system monitoring and detection capabilities to identify potential exploitation attempts and implement additional security controls as needed to protect against this vulnerability. This may involve updating incident response plans and procedures to address potential exploitation of this vulnerability. Furthermore, affected organizations should consider implementing network segmentation and access controls to limit the spread of potential exploitation attempts. They should also verify that their current security controls and processes are adequate to detect and respond to potential exploitation attempts related to this vulnerability. Finally, they should ensure that their incident response plans are updated to address potential exploitation of this vulnerability and that relevant personnel are trained on the updated plans and procedures. The vulnerability's medium severity level and potential impact on business operations and security posture necessitate prompt attention and remediation efforts from affected organizations. The affected devices are widely used in building automation and control systems, which makes them a critical component of many organizations' infrastructure. Therefore, it is essential for organizations to prioritize patching and implementing compensating controls to mitigate the vulnerability and prevent potential exploitation attempts. Organizations should also consider implementing additional security controls, such as monitoring and detection capabilities, to identify and respond to potential exploitation attempts related to this ...
Technical summary
The vulnerability affects Desigo devices, specifically DXR2, PXC3, PXC4, PXC5.E003, PXC5.E24, and PXC7, with various versions being vulnerable. An attacker can exploit this issue by sending a malformed BACnet packet, causing a denial-of-service condition that prevents the device from responding to BACnet queries. This requires a device reset or reboot to restore normal functionality. The vulnerability has a CVSS score of 5.3 and a medium severity level. Affected organizations should prioritize patching and implementing compensating controls to mitigate the vulnerability.
Defensive priority
Medium-priority defensive actions are required to address the vulnerability.
Recommended defensive actions
- Inventory and assess affected Desigo devices
- Apply vendor-provided patches or updates
- Implement compensating controls, such as network segmentation and monitoring
- Verify device configurations and settings
- Review system monitoring and detection capabilities to identify potential exploitation attempts
- Update incident response plans and procedures to address potential exploitation of this vulnerability
- Ensure that relevant personnel are trained on the updated plans and procedures
Evidence notes
The CVE record and NVD entry provide details about the vulnerability. However, additional information from the vendor and other sources may be necessary to fully understand the vulnerability. Affected organizations should verify their deployments, assess potential exposure, and review vendor-provided guidance for patching and mitigation. Defensive priorities should focus on verifying device configurations, implementing compensating controls, and monitoring for potential exploitation attempts. Evidence is limited to public sources and may not reflect all affected systems or potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-59693 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-59693
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-59693 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-59693
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-781903.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.