CVE-2026-59693
Received
Received - Intake
Buffer Overflow in Desigo Building Automation Systems
Vulnerability report for CVE-2026-59693, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-11
Last updated on: 2026-08-11
Assigner: Siemens AG
Description
Description
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715). The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| siemens | desigo_dxr2 | to 01.21.233.16-7862 (exc) |
| siemens | desigo_pxc3 | to 01.21.233.16-7862 (exc) |
| siemens | desigo_pxc4 | to 02.21.194.36-2715 (exc) |
| siemens | desigo_pxc5.e003 | to 02.21.194.36-2715 (exc) |
| siemens | desigo_pxc5.e24 | to 02.21.194.36-2715 (exc) |
| siemens | desigo_pxc7 | to 02.21.194.36-2715 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-754 | The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product. |