EXECUTIVE SUMMARY:
CVE-2026-59693 with a CVSS score of 3.3 is a denial-of-service vulnerability affecting Siemens Desigo DXR and PXC Controllers. Specific impacted versions include Desigo DXR2 prior to V01.21.233.16-7862, Desigo PXC3 prior to V01.21.233.16-7862, and Desigo PXC4, PXC5.E003, PXC5.E24, and PXC7 prior to V02.21.194.36-2715. This flaw stems from an improper check for unusual or exceptional conditions within the device's processing logic, specifically concerning how it handles incoming network traffic. An attacker can exploit this issue by sending a specifically crafted malformed BACnet packet to the targeted device via an adjacent network, requiring no user interaction or privileges. Successful exploitation causes the device to stop responding to BACnet queries, effectively disrupting its communication capabilities. This halt in functionality necessitates a manual device reset or reboot to restore operations, potentially causing significant downtime and operational disruption in critical infrastructure sectors. Exploitation is dependent on the attacker's ability to deliver the malicious packet to the target controller over the network segment where the BACnet protocol is[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
CVE-2026-59693 with a CVSS score of 3.3 is a denial-of-service vulnerability affecting Siemens Desigo DXR and PXC Controllers. Specific impacted versions include Desigo DXR2 prior to V01.21.233.16-7862, Desigo PXC3 prior to V01.21.233.16-7862, and Desigo PXC4, PXC5.E003, PXC5.E24, and PXC7 prior to V02.21.194.36-2715. This flaw stems from an improper check for unusual or exceptional conditions within the device's processing logic, specifically concerning how it handles incoming network traffic. An attacker can exploit this issue by sending a specifically crafted malformed BACnet packet to the targeted device via an adjacent network, requiring no user interaction or privileges. Successful exploitation causes the device to stop responding to BACnet queries, effectively disrupting its communication capabilities. This halt in functionality necessitates a manual device reset or reboot to restore operations, potentially causing significant downtime and operational disruption in critical infrastructure sectors. Exploitation is dependent on the attacker's ability to deliver the malicious packet to the target controller over the network segment where the BACnet protocol is[emaillocker id="1283"]
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-08