CVE-2026-59693Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715). The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-11); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-11: 2Mentions · 2026-08-14: 1Technical Details · 2026-08-14: 108-1108-14
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-112
Disclosure2
2026-08-141
Disclosure1
Full discourse3 posts
  • Aviatrix Threat Research Center@aviatrixtrc
    Disclosure

    TRC analysis shows attackers can crash Siemens Desigo controllers by sending malformed BACnet packets (CVE-2026-59693). The vulnerability causes complete device unresponsiveness, requiring manual resets to restore building automation functionality. Critical infrastructure environments face operational disruption until patched. #CriticalInfrastructure #Vulnerability 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/icsa-26-225-08-cve-2026-59693

    Post summary

    The post announces a new crash vulnerability (CVE‑2026‑59693) in Siemens Desigo controllers triggered by malformed BACnet packets, highlighting potential operational disruption in critical infrastructure until a patch is applied.

    0000066
    1.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-59693 A vulnerability has been identified in Desigo DXR2 (All versions &lt; V01.21.233.16-7862), Desigo PXC3 (All versions &lt; V01.21.233.16-7862), Desigo PXC4 (All versions &lt; V… https://www.cve.org/CVERecord?id=CVE-2026-59693 ----- Traducción: CVE-2026-59693 Se … http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑59693, states affected Desigo product versions, and links to the CVE record without providing PoC, exploit, or mitigation details.

    0000039
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-59693 A vulnerability has been identified in Desigo DXR2 (All versions &lt; V01.21.233.16-7862), Desigo PXC3 (All versions &lt; V01.21.233.16-7862), Desigo PXC4 (All versions &lt; V… https://www.cve.org/CVERecord?id=CVE-2026-59693

    Post summary

    CVE-2026-59693 identifies a vulnerability in multiple Desigo DXR2, PXC3, and PXC4 product versions, but provides no further technical details, exploit information, or patch status.

    00000912
    57.9K followersView on X

Explore more