Impact
A denial‑of‑service vulnerability exists in Siemens Desigo devices, allowing an attacker to interrupt normal operation by sending a malformed BACnet packet. The attack causes the device to stop responding to BACnet queries until the device is reset or rebooted. The weakness is identified as resource exhaustion via input validation failure (CWE‑754). The impact is loss of availability of the affected Desigo device to BACnet clients.
Affected Systems
The vulnerable product family includes Siemens Desigo DXR2, Desigo PXC3, Desigo PXC4, Desigo PXC5.E003, Desigo PXC5.E24, and Desigo PXC7. Versions lower than V01.21.233.16-7862 on DXR2 and PXC3, or lower than V02.21.194.36-2715 on PXC4, PXC5.E003, PXC5.E24, and PXC7, are affected. Those devices can be found in building automation networks that use BACnet.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and EPSS data is not provided, so exploitation probability is unknown. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires an actor with network access to the BACnet domain that can send crafted packets to the target. Once an attack is carried out, the device remains unresponsive until a manual reset or reboot is performed.
OpenCVE Enrichment