CVE-2026-59693
Received Received - Intake

Buffer Overflow in Desigo Building Automation Systems

Vulnerability report for CVE-2026-59693, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Siemens AG

Description

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715). The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
siemens desigo_dxr2 to 01.21.233.16-7862 (exc)
siemens desigo_pxc3 to 01.21.233.16-7862 (exc)
siemens desigo_pxc4 to 02.21.194.36-2715 (exc)
siemens desigo_pxc5.e003 to 02.21.194.36-2715 (exc)
siemens desigo_pxc5.e24 to 02.21.194.36-2715 (exc)
siemens desigo_pxc7 to 02.21.194.36-2715 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-754 The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial-of-service (DoS) vulnerability affecting Siemens Desigo DXR2, PXC3, PXC4, PXC5.E003, PXC5.E24, and PXC7 controllers running outdated firmware. An attacker can send a malformed BACnet packet to crash the device, stopping it from responding to BACnet queries. Recovery requires a device reset or reboot.

Detection Guidance

Detecting this vulnerability requires monitoring for malformed BACnet packets targeting Siemens Desigo controllers. Use network traffic analyzers like Wireshark to inspect BACnet traffic for unusual patterns or malformed packets. Check device logs for repeated crashes or unresponsiveness to BACnet queries. Siemens recommends using their tools or industrial security solutions to scan for vulnerable firmware versions.

Impact Analysis

The vulnerability can disrupt building automation systems by causing affected controllers to stop responding. This may lead to loss of control over HVAC, lighting, or security systems, potentially causing operational downtime or safety risks in facilities using these devices.

Mitigation Strategies

Immediately update affected Siemens Desigo devices to the latest firmware versions (V01.21.233.16-7862 for DXR2/PXC3 or V02.21.194.36-2715 for PXC4/5/7). Restrict network access to these devices by isolating them in a dedicated VLAN or using firewalls. Monitor devices for signs of exploitation and prepare for potential device resets if disruption occurs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59693. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart