Our takeSiemens patched a DoS flaw in Desigo DXR and PXC building-automation controllers: malformed BACnet packets knock the device over and only a reset or reboot brings it back. If you run these — building operators of any size — update now and keep BACnet off the internet.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:Update Desigo DXR and PXC controllers to the versions listed in ICSA-26-225-08. The vulnerability allows remote denial-of-service via malformed BACnet packets; devices require a manual reboot to recover.
What this means for you — Lean IT orgs:If you use Siemens Desigo building automation controllers, apply the vendor updates now. Most offices without these systems can ignore this advisory.
What this means for you — MSP:Check client environments for Siemens Desigo DXR or PXC controllers and schedule the firmware updates from ICSA-26-225-08. Affected devices can be knocked offline remotely by malformed BACnet traffic and need a reboot to recover.
What this means for you — Researcher:Siemens released fixes for a malformed-BACnet-packet denial-of-service flaw in Desigo DXR and PXC controllers per CISA advisory ICSA-26-225-08.