SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.
The following versions of Siemens SIMATIC S7-PLCSIM Advanced are affected:
SIMATIC S7-PLCSIM Advanced vers:all/* (CVE-2026-54429)
Vendor
Equipment
Siemens
Siemens SIMATIC S7-PLCSIM Advanced
Allocation of Resources Without Limits or Throttling
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a denial-of-service condi...
Read the full advisory on CISA →