Siemens Desigo DXR and PXC building automation controllers contain a denial-of-service vulnerability (CVE-2026-59693) caused by improper handling of malformed BACnet packets. An attacker on the same network segment can send crafted packets that cause affected devices to stop responding to BACnet queries, requiring a manual reset or reboot. Siemens has released firmware updates for all affected product lines.
Siemens Desigo
1 post
Siemens Desigo DXR and PXC Controllers (CVE-2026-59693)