Security readout for executives and security teams
Plain-English summary
This flaw can disrupt Siemens Desigo building controllers. A specific BACnet packet can trigger an exception, stop BACnet communication, and potentially put the controller into a factory reset state. That makes the main business concern operational disruption in facilities using affected controllers.
Executive priority
Prioritize remediation where affected controllers support critical facilities, safety-adjacent building operations, or high-availability sites. The issue is availability-focused, but factory reset behavior could create meaningful operational downtime.
Technical view
CVE-2021-41545 is a CWE-248 uncaught exception issue in Siemens Desigo DXR2, PXC3, PXC4, and PXC5 controllers below listed versions. The fault is triggered by a specific BACnet protocol packet and affects controller availability by putting BACnet communication out of work and possibly causing factory reset behavior.
Likely exposure
Exposure is likely limited to environments running affected Siemens Desigo controller versions where BACnet traffic can reach the device. The source bundle does not establish internet exposure, exploit availability, or affected deployment prevalence.
Exploitation context
The sources describe a specific BACnet packet as the trigger. There is no KEV listing and no cited evidence of active exploitation. Treat exploit status as unconfirmed based on the provided sources.
Researcher notes
Evidence is limited to the CVE description and Siemens advisory reference. No CVSS vector, patch detail beyond affected version thresholds, exploit proof, or active exploitation claim is included in the provided bundle.
Mitigation direction
- Identify Siemens Desigo DXR2, PXC3, PXC4, and PXC5 controllers in building networks.
- Upgrade affected controllers to versions at or above the non-affected thresholds listed by Siemens/CVE.
- Restrict BACnet access to trusted management networks and authorized systems.
- Review Siemens advisory SSA-662649 for product-specific update and operational guidance.
Validation and detection
- Inventory controller model and firmware version against the affected version ranges.
- Confirm BACnet interfaces are not reachable from untrusted networks.
- Review network segmentation and access controls around building automation systems.
- Check maintenance records for Siemens advisory SSA-662649 remediation status.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-248: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2021-41545 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://cert-portal.siemens.com/productcert/pdf/ssa-662649.pdfCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Uncaught Exception
Uncaught Exception represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
