Cyber Resilience
← All news
Confirmed

Siemens Desigo DXR and PXC Controllers

Our takeSiemens Desigo DXR/PXC controllers can be knocked offline by malformed BACnet packets, requiring a manual reset to recover. Siemens has patched versions available. These run building automation in facilities of every size, including small operators. Update now.
Sources (1)
What this means for you — Security leader:Siemens released updates for a DoS vulnerability in Desigo DXR and PXC controllers exploitable via malformed BACnet packets. Update to the latest firmware immediately if you operate these building automation systems.
What this means for you — Lean IT orgs:If you run Siemens Desigo DXR or PXC controllers for building systems, apply the new firmware versions as soon as possible. A device reset or reboot is needed to recover from an attack.
What this means for you — MSP:Check client environments for Siemens Desigo DXR and PXC controllers; push the vendor's latest firmware to mitigate a DoS flaw triggered by malformed BACnet packets. Recovery requires a reboot.
What this means for you — Researcher:CISA advisory ICSA-26-225-08 details a DoS vulnerability in Siemens Desigo DXR and PXC controllers via malformed BACnet packets, with vendor fixes now available.