Full Report
SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
Analysis Summary
# Vulnerability: Denial of Service in SIMATIC S7-PLCSIM Advanced
## CVE Details
- **CVE ID:** CVE-2026-54429
- **CVSS Score:**
- CVSS v3.1: 7.4 (High)
- CVSS v4.0: 6.0 (Medium)
- **CWE:** CWE-770: Allocation of Resources Without Limits or Throttling
## Affected Systems
- **Products:** SIMATIC S7-PLCSIM Advanced
- **Versions:** All versions currently available (as of 2026-07-14)
- **Configurations:** Systems configured for external communication (TCP/IP) or using the S7-PLCSIM Virtual Switch. The default "Softbus" mode is not affected.
## Vulnerability Description
The application fails to properly manage high-volume multicast network traffic. An attacker can send a flood of multicast packets to the network segment where the PLCSIM instance is hosted, leading to memory resource exhaustion. This causes the application to become unresponsive (Denial of Service), requiring a manual restart to restore functionality.
## Exploitation
- **Status:** No reports of exploitation in the wild; no Public PoC currently listed.
- **Complexity:** Low (requires specific project configuration to be active).
- **Attack Vector:** Adjacent (Attacker must be on the same local network segment to send multicast traffic).
## Impact
- **Confidentiality:** None
- **Integrity:** None
- **Availability:** High (Application becomes inaccessible and requires manual intervention; however, no project data is lost).
## Remediation
### Patches
- **No patches currently available.** Siemens is currently preparing fix versions.
### Workarounds
* **Restrict Multicast Traffic:** Implement network-level filtering to restrict multicast traffic on the segment hosting the SIMATIC S7-PLCSIM Advanced host.
* **Disable Virtual Switch Binding:** Unbind the S7-PLCSIM Virtual Switch from the network adapter. This removes the external communication capability and the attack vector.
* **Use 'Softbus' Mode:** Configure the instance to use "Softbus" / "PLCSIM" network mode. This is the default mode and does not accept external network packets.
## Detection
- **Indicators of Compromise:** High memory consumption by the PLCSIM process and unusual spikes in multicast traffic on the local network segment.
- **Detection methods and tools:** Network monitoring tools (e.g., Wireshark, Zeek) to identify multicast flooding and system performance monitoring to track memory exhaustion.
## References
- **Vendor Advisory:** hxxps://cert-portal[.]siemens[.]com/productcert/html/ssa-828211[.]html
- **Operational Guidelines:** hxxps://www[.]siemens[.]com/cert/operational-guidelines-industrial-security
- **Product Manuals:**
- hxxps://support[.]industry[.]siemens[.]com/cs/ww/en/view/109997788/
- hxxps://support[.]industry[.]siemens[.]com/cs/ww/en/view/109997789/