Siemens Desigo Improper Check for Unusual or Exceptional Conditions (CVE-2026-59693)

medium Tenable OT Security Plugin ID 506030

Synopsis

The remote OT asset is affected by a vulnerability.

Description

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715).
The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Siemens has released new versions for the affected products and recommends to update to the latest versions:

- Desigo DXR2: Update to V01.21.233.16-7862 or later version
- Desigo PXC3: Update to V01.21.233.16-7862 or later version
- Desigo PXC4: Update to V02.21.194.36-2715 or later version
- Desigo PXC5.E003: Update to V02.21.194.36-2715 or later version
- Desigo PXC5.E24: Update to V02.21.194.36-2715 or later version
- Desigo PXC7: Update to V02.21.194.36-2715 or later version

Please contact your local Siemens office for additional support in obtaining the update.

For additional information, please refer to Siemens Security Advisory SSA-781903

See Also

https://cert-portal.siemens.com/productcert/html/ssa-781903.html

Plugin Details

Severity: Medium

ID: 506030

File Name: tenable_ot_siemens_CVE-2026-59693.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 10/2/2026

Updated: 10/2/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3.2

Percentile: 50.52

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Vulnerability Information

CPE: cpe:/o:siemens:desigo_dxr2_firmware, cpe:/o:siemens:desigo_pxc3_firmware, cpe:/o:siemens:desigo_pxc4_firmware, cpe:/o:siemens:desigo_pxc5.e003_firmware, cpe:/o:siemens:desigo_pxc5.e24_firmware, cpe:/o:siemens:desigo_pxc7_firmware

Required KB Items: Tenable.ot/Siemens

Patch Publication Date: 8/11/2026

Vulnerability Publication Date: 8/11/2026

Reference Information

CVE: CVE-2026-59693

CWE: 754