Executive brief
Siemens SIMATIC S7-PLCSIM Advanced, a software tool used to simulate industrial controllers, is vulnerable to a denial-of-service attack. An attacker on the same local network can send a high volume of specific network traffic to crash the application by exhausting its memory. While no project data is lost, the simulation will become unresponsive and require a manual restart to restore operations.
Technical details
A resource exhaustion vulnerability (CWE-770) exists in SIMATIC S7-PLCSIM Advanced due to improper handling of high-volume multicast network traffic. An unauthenticated attacker on the same local network segment (Layer 2) can exploit this by flooding the application with multicast packets, leading to memory exhaustion and a denial-of-service (DoS) state. Exploitation requires the targeted instance to have a specific project configuration active, specifically one using the S7-PLCSIM Virtual Switch binding. Currently, no patch is available, but mitigations include restricting multicast traffic or using the 'Softbus' network mode which does not accept external network packets.
Affected products
- Siemens SIMATIC S7-PLCSIM Advanced All versions
Timeline
- 2026-07-14: advisory: Initial publication by Siemens ProductCERT
- 2026-07-14: disclosed