Siemens Desigo PX Web Module Insufficient Entropy Vulnerability
The Desigo PX Web module (all firmware versions before v6.00.046) uses insufficient entropy when generating session tokens or cryptographic keys. This weakness allows an attacker with network access to predict or brute-force valid authentication tokens without valid user credentials, potentially gaining unauthorized access to the building automation controller's web interface. The vulnerability affects multiple Desigo PX controller models with Web modules, allowing remote access to configuration and operational functions. No patch is available; the affected firmware versions have reached end-of-support status.
- Network connectivity to the Desigo PX controller's HTTP/HTTPS port (typically 80/443)
- No valid user credentials required
- Access from network segment where the controller is reachable
Patching may require device reboot — plan for process interruption
/api/v1/advisories/ccec20d7-87d2-44e3-8cd5-8ae7dd697979Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.