CVE-2026-54429 Details
Description
A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a denial-of-service condition of the affected application. The affected application becomes inaccessible and requires a manual restart; no project data is lost. Successful exploitation requires a specific project configuration to be already active on the targeted instance.
A denial-of-service vulnerability has been identified in Siemens SIMATIC S7-PLCSIM Advanced, affecting all versions. The issue arises because the application does not properly manage high-volume multicast network traffic, leading to memory exhaustion. This flaw can be exploited by an unauthenticated attacker on the local network segment, causing the application to become inaccessible and requiring a manual restart, although no project data is lost. Successful exploitation depends on having a specific project configuration active on the targeted instance.
Currently, no fix is available. However, Siemens recommends restricting multicast traffic on the network segment where SIMATIC S7-PLCSIM Advanced is running. Users can also disable the S7-PLCSIM Virtual Switch binding on the network adapter used by the affected instance, which removes the attack vector entirely. Alternatively, 'Softbus' or 'PLCSIM' network modes can be used, as these do not accept any packets from the network. For general security, Siemens advises protecting network access to devices and following operational guidelines for Industrial Security.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2026CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-828211.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Siemens SIMATIC S7-PLCSIM Advanced | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |
Volerion