Published Security3 min read
One malformed BACnet packet, one truck roll: Siemens Desigo controllers stay down until reset
CISA advisory ICSA-26-225-08 says a malformed BACnet packet stops Desigo DXR and PXC controllers answering queries, and recovery needs a device reset or reboot. Fixed firmware exists for six models.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- CISA published ICS advisory ICSA-26-225-08, "Siemens Desigo DXR and PXC Controllers", describing a vulnerability that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets.
- The vulnerability is tracked as CVE-2026-59693.
- An attacker can exploit the issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries.
- Recovery requires a device reset or reboot to restore normal functionality.
- Affected versions include Desigo DXR2 below V01.21.233.16-7862 and Desigo PXC3 below V01.21.233.16-7862.
Compiled by The WatchSomething wrong?How this is made
Why it matters
CISA has published advisory ICSA-26-225-08 covering a denial-of-service flaw in Siemens Desigo DXR and PXC building automation controllers, tracked as CVE-2026-59693 [1][2]. A malformed BACnet packet makes an affected controller stop responding to BACnet queries, and the only recovery the advisory describes is a device reset or reboot [3][4][15].
That recovery requirement is the part worth budgeting for. A denial of service that clears itself on the next poll is a monitoring blip; one that persists until somebody physically resets or power-cycles the controller is a work order, a site visit and an escort in sectors where the plant room is not casually accessible. Siemens lists these controllers as deployed worldwide across commercial facilities, critical manufacturing, energy, healthcare and public health, and transportation systems [12][13].
The affected inventory is six product designations split across two firmware branches [9]. Desigo DXR2 and PXC3 are affected below V01.21.233.16-7862, and PXC4, PXC5.E003, PXC5.E24 and PXC7 below V02.21.194.36-2715 [5][6]. Siemens has released new versions and recommends updating to those builds or later [20][7]. The advisory also tells asset owners to contact their local Siemens office for additional support in obtaining the update, which is not the same thing as a self-service download [8].
The underlying weakness is classed as CWE-754, improper check for unusual or exceptional conditions [10]. The finding is credited to Thomas EBI of Sauter, who reported it to Siemens [11]. As published, the advisory's metrics section carries no CVSS score, and it does not state whether the malformed packet requires authentication or must originate on the local segment [14][19]. Anyone triaging this should treat the exploitability details as unknown rather than assume they are benign.
Mitigation advice is the usual perimeter language, and it matters more than normal here because the fix path involves touching firmware on field panels. Siemens recommends protecting network access to the devices with appropriate mechanisms and configuring the environment per its operational guidelines for industrial security [17]. CISA recommends minimising network exposure, keeping control system devices off the internet, placing control networks and remote devices behind firewalls and isolated from business networks, and using more secure remote access methods such as VPNs while recognising that a VPN is only as secure as the devices connected to it [16]. CISA also reminds organisations to perform impact analysis and risk assessment before deploying defensive measures [18].
What to watch. First, inventory by exact model string, because the PXC5 variants are enumerated separately and a partial upgrade leaves the same failure mode in place [6]. Second, work out now who resets a hung controller and how long that takes at your worst site, because the answer to that question is the real severity of this bug, not any score [4][15]. Third, check what can reach BACnet on your controller segments today, including engineering workstations, integration gateways and third-party analytics platforms, since the advisory frames exposure control as the primary compensating measure [16][17]. Fourth, start the firmware conversation with the local Siemens office early, given that the advisory routes update acquisition through them [8].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
CISA published ICS advisory ICSA-26-225-08, "Siemens Desigo DXR and PXC Controllers", describing a vulnerability that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets.
- [2]
The vulnerability is tracked as CVE-2026-59693.
- [3]
An attacker can exploit the issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries.
- [4]
Recovery requires a device reset or reboot to restore normal functionality.
- [5]
Affected versions include Desigo DXR2 below V01.21.233.16-7862 and Desigo PXC3 below V01.21.233.16-7862.
- [6]
Affected versions include Desigo PXC4, PXC5.E003, PXC5.E24 and PXC7 below V02.21.194.36-2715.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cisa.govCISAAug 13Siemens Desigo DXR and PXC Controllers
Additional citations
- CISA
- CISA advisory ICSA-26-225-08
- CISA advisory ICSA-26-225-08 acknowledgments
- CISA advisory ICSA-26-225-08, quoting Siemens general recommendations



