Siemens Desigo DXR and PXC Controllers

MonitorCVSS 4.3ICS-CERT ICSA-26-225-08Aug 11, 2026
Siemens
Attack path
Attack VectorAdjacent
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A denial of service vulnerability in Siemens Desigo DXR2, PXC3, PXC4, PXC5.E003, PXC5.E24, and PXC7 controllers allows an attacker to send malformed BACnet packets that crash or hang the device. Recovery requires manual reset or reboot. Siemens has released firmware updates to resolve this issue.

What this means
What could happen
An attacker on the network can send malformed BACnet packets to crash or hang Desigo controllers, requiring a manual reset or reboot to restore control operations. This causes temporary loss of building automation for HVAC, lighting, and security systems.
Who's at risk
Building automation and facilities management teams operating Siemens Desigo building controls. This impacts HVAC systems, lighting control, security integrations, and energy management systems in commercial buildings, hospitals, data centers, and industrial facilities that rely on DXR or PXC controllers.
How it could be exploited
An attacker with network access to a Desigo DXR or PXC controller sends crafted BACnet protocol packets. The vulnerable device processes the malformed packets incorrectly, triggering a denial of service condition that makes the controller unresponsive until manually rebooted.
Prerequisites
  • Network access to the BACnet port on the target Desigo controller
  • No authentication required
remotely exploitableno authentication requiredlow complexityaffects building operations
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (6)
6 with fix
ProductAffected VersionsFix Status
Desigo DXR2 < V01.21.233.16-7862< 01.21.233.16-786201.21.233.16-7862
Desigo PXC3 < V01.21.233.16-7862< 01.21.233.16-786201.21.233.16-7862
Desigo PXC4 < V02.21.194.36-2715< 02.21.194.36-271502.21.194.36-2715
Desigo PXC5.E003 < V02.21.194.36-2715< 02.21.194.36-271502.21.194.36-2715
Desigo PXC5.E24 < V02.21.194.36-2715< 02.21.194.36-271502.21.194.36-2715
Desigo PXC7 < V02.21.194.36-2715< 02.21.194.36-271502.21.194.36-2715
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict network access to BACnet ports (UDP 47808 standard) on Desigo controllers to only authorized building automation workstations and engineering systems
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Desigo DXR2 and PXC3 controllers to firmware version 01.21.233.16-7862 or later
HOTFIXUpdate Desigo PXC4, PXC5.E003, PXC5.E24, and PXC7 controllers to firmware version 02.21.194.36-2715 or later
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate Desigo controllers on a separate VLAN from untrusted networks if not already done
API: /api/v1/advisories/72e00cbf-dcef-414f-b674-2b7716cc82a8

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Siemens Desigo DXR and PXC Controllers | CVSS 4.3 - OTPulse