discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Siemens Desigo DXR and PXC Controllers Vulnerable to Denial-of-Service Attacks

A vulnerability in Siemens Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality.

By CISA·Aug 13·cisa.gov·2 min read

Intelligence analysis by Llama

Siemens has released new versions for the affected products and recommends updating to the latest versions. The affected devices are vulnerable to a denial-of-service (DoS) vulnerability, which can be exploited by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries.

Why it matters

This vulnerability affects critical infrastructure sectors, including commercial facilities, critical manufacturing, energy, healthcare and public health, and transportation systems. It is essential to update the affected devices to the latest versions to prevent potential attacks.

Imagine you're trying to talk to a device, but it's not responding because someone sent it a weird message. That's what's happening with these Siemens devices - they're not working because of a bad message. To fix it, you need to update the device to the latest version.

Analysis

Background

A vulnerability in Siemens Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. This vulnerability affects critical infrastructure sectors, including commercial facilities, critical manufacturing, energy, healthcare and public health, and transportation systems.

Affected Products

The following versions of Siemens Desigo DXR and PXC Controllers are affected:

  • Desigo DXR2 vers:intdot/<01.21.233.16-7862 (CVE-2026-59693)
  • Desigo PXC3 vers:intdot/<01.21.233.16-7862 (CVE-2026-59693)
  • Desigo PXC4 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693)
  • Desigo PXC5.E003 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693)
  • Desigo PXC5.E24 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693)
  • Desigo PXC7 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693)

Remediations

Siemens has released new versions for the affected products and recommends updating to the latest versions. The affected devices are vulnerable to a denial-of-service (DoS) vulnerability, which can be exploited by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries.

General Recommendations

As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and following the recommendations in the product manuals.

Key points

  • A vulnerability in Siemens Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets.
  • The affected devices are vulnerable to a denial-of-service (DoS) vulnerability, which can be exploited by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries.
  • Siemens has released new versions for the affected products and recommends updating to the latest versions.
The Upside

If this vulnerability is addressed promptly, the affected devices can be updated to the latest versions, preventing potential attacks and ensuring the continued operation of critical infrastructure.

The Downside

If the vulnerability is not addressed, the affected devices may remain vulnerable to denial-of-service attacks, potentially leading to disruptions in critical infrastructure services.

Originally reported at

cisa.gov

Discernion covers the story. Read the full piece at the source.

Tagsics-advisoriesindustrial-control-systemsvulnerabilitiesdenial-of-servicesiemensdesigo-dxrdesigo-pxc

Author

CISA

Intelligence analysis by

Llama

Published

Aug 13, 2026

Source

cisa.gov

Share

Topics

ics-advisoriesindustrial-control-systemsvulnerabilitiesdenial-of-servicesiemensdesigo-dxrdesigo-pxc

Related

More from this desk

Aug 24·bleepingcomputer.com

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities can be used to forge SAML responses and log in as administrators.

Aug 24·bleepingcomputer.com

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA).

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·thehackernews.com

Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

U.S. agencies warn of AI-powered attacks on Siemens S7 Series PLCs as a GitLab code-injection flaw (CVE-2026-19478) faces active exploitation, alongside npm supply-chain attacks and suspected Russian espionage clusters.