CVE-2026-59693: Medium severity Siemens Desigo Dxr2 vulnerability
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715). The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Desigo DXR2to a version that resolves this vulnerability.Fixed in V01.21.233.16-7862 - Upgrade
Upgrade
Desigo PXC3to a version that resolves this vulnerability.Fixed in V01.21.233.16-7862 - Upgrade
Upgrade
Desigo PXC4to a version that resolves this vulnerability.Fixed in V02.21.194.36-2715 - Upgrade
Upgrade
Desigo PXC5.E003to a version that resolves this vulnerability.Fixed in V02.21.194.36-2715 - Upgrade
Upgrade
Desigo PXC5.E24to a version that resolves this vulnerability.Fixed in V02.21.194.36-2715 - Upgrade
Upgrade
Desigo PXC7to a version that resolves this vulnerability.Fixed in V02.21.194.36-2715 - Operational
If the BACnet service stops responding, perform a device reset or reboot to restore normal BACnet functionality.