Denial-of-Service Vulnerability in Siemens Desigo Products
CVE-2026-59693

5.3MEDIUM

Key Information:

Vendor

Siemens

Vendor
CVE Published:
11 August 2026

What is CVE-2026-59693?

A denial-of-service vulnerability has been identified in several Siemens Desigo product lines, allowing attackers to disrupt the normal operations of devices. By sending a malformed BACnet packet, an attacker can render the affected devices unresponsive to BACnet queries. Restoration of service necessitates either a manual device reset or reboot, which can lead to potential downtime and increased maintenance efforts.

Affected Version(s)

Desigo DXR2 0

Desigo PXC3 0

Desigo PXC4 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.