# Unauthenticated Remote Access Flaws in Siemens Desigo Building Controllers Threaten Critical Facilities
## The Threat
Siemens Desigo DXR and PXC series controllers — the hardware quietly managing HVAC systems, access control, and energy infrastructure in hospitals, airports, office campuses, and industrial facilities — carry a cluster of vulnerabilities that could allow unauthenticated remote attackers to seize control or crash the devices entirely. CISA has published a coordinated advisory flagging multiple weaknesses across the product lines, ranging from hard-coded credentials baked into firmware to buffer overflow conditions reachable over the network without authentication.
What makes this more than a routine patch advisory is context: these aren't web servers or desktops sitting behind layers of defense. Desigo DXR and PXC units are often deployed in operational technology (OT) environments where network segmentation is inconsistent, patch cycles are measured in years, and rebooting a controller mid-winter in a hospital is simply not an option someone will take lightly. That operational reality is exactly why attackers — whether ransomware operators pivoting from IT to OT or nation-state actors with infrastructure targeting mandates — find building automation systems attractive. They're under-monitored, under-patched, and deeply embedded in physical operations.
The hard-coded credential finding is particularly concerning. Hard-coded credentials don't degrade over time and can't be rotated by an administrator — once the credential is extracted from firmware (a task any motivated researcher can accomplish), every device running that firmware version is permanently compromised unless it receives a patch. The buffer overflow vulnerabilities compound the risk: an attacker who can crash or take over the controller's network stack may be able to pivot deeper into the building management network or cause physical disruption to the systems the controller manages.
## Severity and Impact
| CVE | CVSS Score | Severity | Vector String | Attack Complexity | Auth Required | CWE |
|-----|-----------|----------|--------------|-------------------|---------------|-----|
| CVE-2022-46351 | 9.8 | Critical | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | Low | None | CWE-120 (Buffer Overflow) |
| CVE-2022-46352 | 9.1 | Critical | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N | Low | None | CWE-22 (Path Traversal) |
| CVE-2022-46353 | 9.8 | Critical | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | Low | None | CWE-306 (Missing Authentication) |
| CVE-2022-46354 | 6.1 | Medium | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | Low | None | CWE-79 (Cross-Site Scripting) |
The critical-severity findings share a damning common thread: no authentication required, low attack complexity, network-accessible. These are not theoretical or chained exploitation paths. An attacker with basic OT tooling and network access to the management interface has a clear shot.
## Affected Products
Desigo DXR2 Series
Desigo PXC3 Series
Desigo PXC4 Series
Desigo PXC5 Series
All four product lines share the vulnerable codebase components. Operators running mixed deployments — a common scenario in large campus environments where controller generations overlap — should treat every device in scope as compromised until patched or isolated.
## Mitigations
Immediate action (firmware update): Siemens has released patched firmware for all affected product lines. This is the definitive fix for the buffer overflow and hard-coded credential vulnerabilities. Operators should prioritize obtaining the patched images from the Siemens ProductCERT portal and scheduling maintenance windows accordingly.
Network segmentation (deploy now, patch later): Controllers should not be reachable directly from corporate IT networks or the open internet. Place Desigo DXR and PXC devices behind a dedicated OT network segment with firewall rules restricting inbound traffic to only known BMS workstations and engineering hosts. If devices are currently internet-facing — and SHODAN searches suggest a non-trivial number are — take them offline immediately until patched.
Disable unused interfaces: The web management interface is the most exposed attack surface. If remote web access is not operationally required, disable it at the device or block it at the network perimeter.
Credential audit: Even after patching, audit all Desigo deployments for default and hard-coded credential usage. Assume any previously exposed device has had its credentials harvested. Rotate any associated accounts that have lateral access to adjacent systems.
Monitoring: Deploy network-level anomaly detection on OT segments watching for unusual BACnet/IP traffic or unexpected access to controller management ports. Building automation systems have highly predictable traffic patterns — deviations stand out.
Compensating controls for deferred patching: Organizations that cannot immediately apply firmware updates (a realistic constraint for 24/7 critical facilities) should implement strict allowlisting of source IPs permitted to reach the controllers and conduct manual inspection of controller logs for signs of exploitation.
## References
---
## HackWire Analysis
The Desigo DXR and PXC advisory lands at an uncomfortable moment for the building automation sector. The last two years have seen a steady escalation of OT-focused ransomware — groups like Volt Typhoon and FIN13 have made industrial control and building automation systems explicit targets, not incidental victims. A cluster of unauthenticated, network-exploitable, critical-severity CVEs in Siemens building controllers is precisely the kind of pre-positioned access those actors look for.
What the standard advisory roundup won't tell you: the physical consequences of compromising these specific controllers are more severe than most people assume. Desigo PXC and DXR units manage more than thermostats. In large facilities, they coordinate pressurization in server rooms, regulate temperature in pharmaceutical cold storage, control HVAC airflows in hospital operating theaters, and manage access control integration. An attacker who can write arbitrary commands to a PXC controller doesn't just disrupt comfort — they can create conditions that damage equipment, invalidate temperature-sensitive inventory, or force facility shutdowns.
The hard-coded credential issue also deserves more attention than it typically gets in advisory summaries. This isn't a configuration mistake by an admin — it's a firmware-level design decision Siemens made, presumably for maintenance or recovery purposes. The implication is that these credentials have existed since the product launched. Anyone who has had legitimate access to Desigo firmware images — including former employees, vendors, or contractors — may already have them. Patching removes the vulnerability, but it doesn't tell you whether the credentials were already used.
Facilities managers and OT security teams should treat this as a high-priority item regardless of how "isolated" they believe their building management networks are. Assumed segmentation and actual segmentation rarely match.
— HackWire Editorial
---
## Related Coverage