Denial-of-Service Vulnerability (CVE‑2026‑59693) in Siemens Desigo DXR & PXC Controllers
What It Is — A CVE‑2026‑59693 flaw in Siemens Desigo DXR and PXC building‑automation controllers allows an attacker to trigger a denial‑of‑service condition by sending malformed BACnet packets. The device must be reset or rebooted to recover.
Exploitability — Publicly disclosed; no known active exploit‑as‑a‑service, but the low CVSS v3 score of 4.3 indicates that crafting the malformed packets is straightforward. Siemens has released firmware patches.
Affected Products — Siemens Desigo DXR2, Desigo PXC3, PXC4, PXC5.E003, PXC5.E24, and PXC7 controllers (all versions prior to the Siemens‑issued updates).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Change Management (CC6.1) requires documented patching of third‑party devices; unpatched controllers leave a control gap.
- Continuous control monitoring must capture firmware‑version evidence to demonstrate due diligence to auditors.
- A DoS event can impair the Availability principle, eroding the trust of enterprise customers who demand demonstrable SOC 2 controls.
Recommended Actions
- Inventory all Desigo DXR/PXC controllers and verify current firmware versions.
- Apply Siemens‑provided firmware updates to the listed models immediately.
- Record the patching activity in your change‑management system and retain logs as SOC 2 audit evidence.
- Enable BACnet traffic monitoring to detect malformed packets as an early‑warning control.
- Update your vendor‑risk register to reflect the remediation status.
Source: CISA Advisory – ICSA‑26‑225‑08