Vulnerability

Denial of Service Vulnerability in Siemens Desigo Building Controllers

FORTSECURE GLOBAL· 2026-08-14🛰 CISA Cybersecurity Advisories
#ICS Security#Building Automation#BACnet#IoT Security

A vulnerability in Desigo DXR and PXC controllers allows for Denial of Service attacks via malformed BACnet packets, impacting building automation stability.

The Impact of BACnet Vulnerabilities on Building Automation

Siemens Desigo DXR and PXC controllers, which are fundamental components in modern building automation systems (BAS), have been found to contain a vulnerability that can be triggered by malformed BACnet packets. BACnet (Building Automation and Control networks) is a standard protocol used for communication between building devices such as HVAC, lighting, and access control. The vulnerability allows a remote attacker to send a specially crafted packet that causes the controller to enter a Denial of Service (DoS) state. In such a state, the controller ceases to function normally, potentially disrupting critical building services. Recovery is not automatic and requires a physical device reset or a manual reboot, which can be time-consuming in large-scale installations.

Risks to Critical Infrastructure and Smart Buildings

The disruption of building controllers is more than just a convenience issue; it is a safety and operational risk. For facilities like hospitals, data centers, or manufacturing plants, the failure of climate control or ventilation systems can lead to equipment overheating or unsafe working conditions. The fact that the attack can be executed over the network via the BACnet protocol makes it a significant threat, especially if the building's automation network is connected to the internet or a poorly secured corporate intranet. This vulnerability underscores the need for robust security protocols in the Internet of Things (IoT) and Industrial Control Systems (ICS) space.

Practical Recommendations for Security Teams

To protect building automation environments, FORTSECURE GLOBAL suggests the following measures:

  1. Firmware Updates: Immediately identify all affected Desigo DXR and PXC controllers and plan a maintenance window to apply the latest firmware updates released by Siemens.
  2. BACnet Traffic Filtering: Use industrial-grade firewalls or deep packet inspection (DPI) tools to monitor and filter BACnet traffic. Block any non-compliant or malformed packets at the network perimeter.
  3. VLAN Segmentation: Isolate the Building Automation System (BAS) on a dedicated VLAN. Ensure there is no direct routing between the BAS network and the general office network or the public internet.
  4. VPN for Remote Access: If remote maintenance is required, ensure it is conducted via a secure, authenticated VPN with multi-factor authentication (MFA), rather than exposing the BACnet ports directly to the internet.

แหล่งที่มา: CISA Cybersecurity Advisories เผยแพร่ครั้งแรก: Thu, 13 Aug 26 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: CISA Cybersecurity Advisories

เผยแพร่ครั้งแรก: Thu, 13 Aug 26 12:00:00 +0000

บทความต้นฉบับ: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-08

อ่านบทความต้นฉบับ ↗

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog