HomeIntelligenceBrief
VULNERABILITY BRIEF🟢 Low Vulnerability

Denial-of-Service Vulnerability (CVE-2026-59693) in Siemens Desigo DXR & PXC Controllers Threatens Building Automation

Siemens Desigo DXR and PXC controllers are vulnerable to a DoS condition when attackers send malformed BACnet packets; remediation requires firmware updates. For SOC 2 teams the issue highlights the need for continuous vendor‑device patch tracking and evidence of change management.

LiveThreat™ Intelligence · 📅 August 13, 2026· 📰 cisa.gov
🟢
Severity
Low
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
1 recommended
📰
Source
cisa.gov

Denial-of-Service Vulnerability (CVE‑2026‑59693) in Siemens Desigo DXR & PXC Controllers

What It Is — A CVE‑2026‑59693 flaw in Siemens Desigo DXR and PXC building‑automation controllers allows an attacker to trigger a denial‑of‑service condition by sending malformed BACnet packets. The device must be reset or rebooted to recover.

Exploitability — Publicly disclosed; no known active exploit‑as‑a‑service, but the low CVSS v3 score of 4.3 indicates that crafting the malformed packets is straightforward. Siemens has released firmware patches.

Affected Products — Siemens Desigo DXR2, Desigo PXC3, PXC4, PXC5.E003, PXC5.E24, and PXC7 controllers (all versions prior to the Siemens‑issued updates).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Change Management (CC6.1) requires documented patching of third‑party devices; unpatched controllers leave a control gap.
  • Continuous control monitoring must capture firmware‑version evidence to demonstrate due diligence to auditors.
  • A DoS event can impair the Availability principle, eroding the trust of enterprise customers who demand demonstrable SOC 2 controls.

Recommended Actions

  • Inventory all Desigo DXR/PXC controllers and verify current firmware versions.
  • Apply Siemens‑provided firmware updates to the listed models immediately.
  • Record the patching activity in your change‑management system and retain logs as SOC 2 audit evidence.
  • Enable BACnet traffic monitoring to detect malformed packets as an early‑warning control.
  • Update your vendor‑risk register to reflect the remediation status.

Source: CISA Advisory – ICSA‑26‑225‑08

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-08

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →