Denial of Service via Multicast Traffic in Siemens SIMATIC S7-PLCSIM Advanced
CVE-2026-54429 Published on July 14, 2026

A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a denial-of-service condition of the affected application. The affected application becomes inaccessible and requires a manual restart; no project data is lost. Successful exploitation requires a specific project configuration to be already active on the targeted instance.

NVD

Weakness Type

Allocation of Resources Without Limits or Throttling

The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.


Products Associated with CVE-2026-54429

Want to know whenever a new CVE is published for Siemens Simatic S7 Plcsim Advanced? stack.watch will email you.

 

Affected Versions

Siemens SIMATIC S7-PLCSIM Advanced: