Siemens Desigo DXR and PXC Controllers Vulnerability Alert
Siemens Desigo DXR and PXC Controllers Vulnerability Alert 🚨
A vulnerability has been identified in Desigo DXR and PXC controllers that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality.
Affected Devices
The following versions of Siemens Desigo DXR and PXC Controllers are affected by this vulnerability (CVE-2026-59693):
- Desigo DXR2 < V01.21.233.16-7862
- Desigo PXC3 < V01.21.233.16-7862
- Desigo PXC4 < V02.21.194.36-2715
- Desigo PXC5.E003 < V02.21.194.36-2715
- Desigo PXC5.E24 < V02.21.194.36-2715
- Desigo PXC7 < V02.21.194.36-2715
These controllers are deployed worldwide across critical infrastructure sectors including Commercial Facilities, Critical Manufacturing, Energy, Healthcare, and Transportation Systems.
Recommended Actions
To remediate this vulnerability, Siemens recommends:
- Updating to V01.21.233.16-7862 or later for Desigo DXR2 and PXC3 controllers.
- For Desigo PXC4, PXC5.E003, PXC5.E24, and PXC7 controllers, update to V02.21.194.36-2715 or later.
Additionally, CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities:
- Minimize network exposure for all control system devices.
- Ensure they are not accessible from the internet.
- Use secure methods for remote access, such as VPNs.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Organizations observing suspected malicious activity should report findings to CISA for tracking and correlation against other incidents.
For more details, read the complete article here: Read full article