Siemens Building Controllers Vulnerable to Network-Based Disruption
Siemens has disclosed a vulnerability affecting its Desigo DXR and PXC controllers, which are commonly used to manage building automation systems such as heating, ventilation, and access control. The flaw, tracked as CVE-2026-59693, allows an attacker to send malformed BACnet network packets to the device, potentially causing it to stop working. Restoring normal operation requires a manual reset or reboot of the affected controller.
While the vulnerability has a moderate severity rating (CVSS 4.3), any disruption to building management systems can have real operational impact, especially for businesses relying on these controllers for climate control, security, or safety systems. Several product lines are affected, including Desigo DXR2, PXC3, PXC4, PXC5, and PXC7, across various firmware versions.
Siemens has released updated firmware that resolves the issue and is urging all customers using the affected controllers to update as soon as possible. Businesses that operate building management systems, particularly those in commercial property, healthcare, and facilities management, should check whether their infrastructure includes any of the listed models.