← Back to Feed
Siemens SIMATIC S7-PLCSIM Advanced
CVE-2026-54429
July 28, 2026 · CISA (US-CERT) · Severity: CRITICAL
A vulnerability in Siemens SIMATIC S7-PLCSIM Advanced allows an unauthenticated attacker to cause a denial of service by sending high-volume multicast traffic. The affected application becomes inaccessible and requires a manual restart, but no project data is lost. Siemens recommends specific mitigations such as disabling the virtual switch binding or restricting multicast traffic.
Key Takeaways
- A denial of service vulnerability in SIMATIC S7-PLCSIM Advanced arises from improper multicast traffic handling.
- Unauthenticated attackers on the local network can exhaust memory resources, causing application inaccessibility.
- Mitigations include disabling virtual switch binding or restricting multicast traffic on the network segment.