← Back to Feed

Siemens SIMATIC S7-PLCSIM Advanced

CVE-2026-54429

July 28, 2026 · CISA (US-CERT) · Severity: CRITICAL

A vulnerability in Siemens SIMATIC S7-PLCSIM Advanced allows an unauthenticated attacker to cause a denial of service by sending high-volume multicast traffic. The affected application becomes inaccessible and requires a manual restart, but no project data is lost. Siemens recommends specific mitigations such as disabling the virtual switch binding or restricting multicast traffic.

Key Takeaways

  • A denial of service vulnerability in SIMATIC S7-PLCSIM Advanced arises from improper multicast traffic handling.
  • Unauthenticated attackers on the local network can exhaust memory resources, causing application inaccessibility.
  • Mitigations include disabling virtual switch binding or restricting multicast traffic on the network segment.
☕ Buy a Coffee