# Siemens S7-PLCSIM Advanced DoS Flaw

Published: 2026-07-28 · Severity: medium · Sectors: manufacturing
Canonical: https://vorant.io/reports/0cae1de9-aca5-5a06-91d0-2d00780d28e4/siemens-s7-plcsim-advanced-dos-flaw

> A memory exhaustion vulnerability in Siemens SIMATIC S7-PLCSIM Advanced lets an unauthenticated local attacker crash the application via multicast traffic flooding.

CISA and Siemens ProductCERT disclosed a denial-of-service vulnerability (CVE-2026-54429) affecting all versions of SIMATIC S7-PLCSIM Advanced, a PLC simulation tool used in industrial engineering environments. The flaw stems from improper handling of high-volume multicast network traffic, which can exhaust memory resources on the host running the affected application. An unauthenticated attacker on the local network segment could trigger this condition, forcing the application to become inaccessible and require a manual restart, though no project data is lost.

Exploitation requires a specific project configuration to already be active on the target instance, somewhat limiting the attack surface. No fix is currently available; Siemens recommends mitigations including disabling the S7-PLCSIM Virtual Switch binding, restricting multicast traffic on the hosting network segment, or using the default 'Softbus'/'PLCSIM' network mode which does not accept external network packets. The vulnerability affects the Critical Manufacturing sector globally, reflecting the tool's use in industrial engineering and simulation workflows tied to Siemens automation products.

This is a routine ICS advisory disclosure with no evidence of active exploitation; the vendor and CISA published it as a coordinated vulnerability disclosure with mitigation guidance while a permanent fix is developed.

## Mentioned in this report

- Vulnerabilities: CVE-2026-54429

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0cae1de9-aca5-5a06-91d0-2d00780d28e4/siemens-s7-plcsim-advanced-dos-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
