CVE-2026-59693: Medium severity Siemens Desigo Dxr2 vulnerability
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715). The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Desigo DXR2to a version that resolves this vulnerability.Fixed in V01.21.233.16-7862 - Upgrade
Upgrade
Desigo PXC3to a version that resolves this vulnerability.Fixed in V01.21.233.16-7862 - Upgrade
Upgrade
Desigo PXC4to a version that resolves this vulnerability.Fixed in V02.21.194.36-2715 - Upgrade
Upgrade
Desigo PXC5.E003to a version that resolves this vulnerability.Fixed in V02.21.194.36-2715 - Upgrade
Upgrade
Desigo PXC5.E24to a version that resolves this vulnerability.Fixed in V02.21.194.36-2715 - Upgrade
Upgrade
Desigo PXC7to a version that resolves this vulnerability.Fixed in V02.21.194.36-2715 - Operational
If the BACnet service stops responding, perform a device reset or reboot to restore normal BACnet functionality.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59693?
The severity of CVE-2026-59693 is medium with a score of 4.3.
How do I fix CVE-2026-59693?
To fix CVE-2026-59693, update to the latest version of the affected Siemens Desigo devices as specified in the vulnerability details.
What systems are affected by CVE-2026-59693?
CVE-2026-59693 affects multiple versions of Siemens Desigo DXR2, PXC3, PXC4, PXC5, and PXC7 devices.
What type of vulnerability is CVE-2026-59693?
CVE-2026-59693 is categorized as a risk associated with certain versions of Siemens Desigo products, potentially affecting availability.
Is there an exploit for CVE-2026-59693?
Currently, there is no public knowledge of a specific exploit for CVE-2026-59693, but it is advisable to mitigate the risk by applying available updates.