HomeIntelligenceBrief
VULNERABILITY BRIEF 🟢 Low Vulnerability

Denial-of-Service Vulnerability (CVE-2026-59693) in Siemens Desigo DXR & PXC Controllers Threatens Building Automation

Siemens Desigo DXR and PXC controllers are vulnerable to a DoS condition when attackers send malformed BACnet packets; remediation requires firmware updates. For SOC 2 teams the issue highlights the need for continuous vendor‑device patch tracking and evidence of change management.

Verisq™ Intelligence · 📅 August 13, 2026 · 📰 cisa.gov
🟢
Severity
Low
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
1 recommended
📰
Source
cisa.gov

Denial-of-Service Vulnerability (CVE‑2026‑59693) in Siemens Desigo DXR & PXC Controllers

What It Is — A CVE‑2026‑59693 flaw in Siemens Desigo DXR and PXC building‑automation controllers allows an attacker to trigger a denial‑of‑service condition by sending malformed BACnet packets. The device must be reset or rebooted to recover.

Exploitability — Publicly disclosed; no known active exploit‑as‑a‑service, but the low CVSS v3 score of 4.3 indicates that crafting the malformed packets is straightforward. Siemens has released firmware patches.

Affected Products — Siemens Desigo DXR2, Desigo PXC3, PXC4, PXC5.E003, PXC5.E24, and PXC7 controllers (all versions prior to the Siemens‑issued updates).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Change Management (CC6.1) requires documented patching of third‑party devices; unpatched controllers leave a control gap.
  • Continuous control monitoring must capture firmware‑version evidence to demonstrate due diligence to auditors.
  • A DoS event can impair the Availability principle, eroding the trust of enterprise customers who demand demonstrable SOC 2 controls.

Recommended Actions

  1. Inventory all Desigo DXR/PXC controllers and verify current firmware versions.
  2. Apply Siemens‑provided firmware updates to the listed models immediately.
  3. Record the patching activity in your change‑management system and retain logs as SOC 2 audit evidence.
  4. Enable BACnet traffic monitoring to detect malformed packets as an early‑warning control.
  5. Update your vendor‑risk register to reflect the remediation status.

Source: CISA Advisory – ICSA‑26‑225‑08

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-08

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →