Description
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715). The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.
Published: 2026-08-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A denial‑of‑service vulnerability exists in Siemens Desigo devices, allowing an attacker to interrupt normal operation by sending a malformed BACnet packet. The attack causes the device to stop responding to BACnet queries until the device is reset or rebooted. The weakness is identified as resource exhaustion via input validation failure (CWE‑754). The impact is loss of availability of the affected Desigo device to BACnet clients.

Affected Systems

The vulnerable product family includes Siemens Desigo DXR2, Desigo PXC3, Desigo PXC4, Desigo PXC5.E003, Desigo PXC5.E24, and Desigo PXC7. Versions lower than V01.21.233.16-7862 on DXR2 and PXC3, or lower than V02.21.194.36-2715 on PXC4, PXC5.E003, PXC5.E24, and PXC7, are affected. Those devices can be found in building automation networks that use BACnet.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and EPSS data is not provided, so exploitation probability is unknown. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires an actor with network access to the BACnet domain that can send crafted packets to the target. Once an attack is carried out, the device remains unresponsive until a manual reset or reboot is performed.

Generated by OpenCVE AI on August 11, 2026 at 23:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the firmware to V01.21.233.16-7862 on Desigo DXR2 and Desigo PXC3 or to V02.21.194.36-2715 on Desigo PXC4, Desigo PXC5.E003, Desigo PXC5.E24, and Desigo PXC7.
  • If an immediate firmware update is not possible, schedule a device reset or reboot after an exploitation attempt to restore service.
  • Apply network segmentation so that only trusted BACnet traffic reaches the vulnerable device and monitor for anomalous BACnet packets that may indicate exploitation attempts.

Generated by OpenCVE AI on August 11, 2026 at 23:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens desigo Dxr2
Siemens desigo Pxc3
Siemens desigo Pxc4
Siemens desigo Pxc5
Siemens desigo Pxc7
Vendors & Products Siemens
Siemens desigo Dxr2
Siemens desigo Pxc3
Siemens desigo Pxc4
Siemens desigo Pxc5
Siemens desigo Pxc7

Wed, 12 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Malformed BACnet Packet in Siemens Desigo Device

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715). The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Desigo Dxr2 Desigo Pxc3 Desigo Pxc4 Desigo Pxc5 Desigo Pxc7
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-08-11T18:08:58.835Z

Reserved: 2026-07-06T13:50:39.917Z

Link: CVE-2026-59693

cve-icon Vulnrichment

Updated: 2026-08-11T18:08:54.580Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T13:19:00.477

Modified: 2026-08-28T19:03:37.837

Link: CVE-2026-59693

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:41:22Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions