Multicast traffic spikes cause memory exhaustion and application crashes in Siemens SIMATIC S7-PLCSIM Advanced
High volumes of multicast network traffic can exhaust memory in Siemens SIMATIC S7-PLCSIM Advanced, causing the application to crash. This vulnerability requires an attacker to be on the local network segment and a specific project configuration to be active. To prevent this, switch your network mode to 'Softbus' or disable the S7-PLCSIM Virtual Switch binding. 馃毃
Summary
A memory exhaustion vulnerability in Siemens SIMATIC S7-PLCSIM Advanced allows unauthenticated attackers on a local network segment to trigger a denial-of-service (DoS) condition. The flaw occurs when the application fails to properly handle high-volume multicast traffic, leading to resource exhaustion that renders the application inaccessible.
While the resulting crash requires a manual restart of the software, Siemens reports that no project data is lost during the event. Successful exploitation depends on an attacker being able to reach the targeted instance and a specific project configuration being active at the time of the attack.
Technical details
The vulnerability, identified as CVE-2026-54429 (CVSS 7.4), centers on how SIMATIC S7-PLCSIM Advanced handles multicast network traffic. When subjected to high volumes of these packets, the application's available memory resources can be exhausted.
SIMATIC S7-PLCSIM Advanced is used to simulate S7-1200, S7-1500, and other PLC derivatives. It includes full network access to simulate PLCs within virtualized environments, which creates the specific attack vector through its virtual switch bindings.
Affected products and fixed versions
The vulnerability affects all versions of SIMATIC S7-PLCSIM Advanced.
Siemens is currently preparing fix versions for this product. Until those updates are released, users should implement the mitigations listed below to reduce risk.
Defender guidance
To mitigate the risk of memory exhaustion via multicast traffic, apply these specific configuration changes:
- Switch Network Mode: Use 'Softbus' or 'PLCSIM' network modes. This mode is a default setting and does not accept any packets from the network, effectively neutralizing the attack vector.
- Disable Virtual Switch Binding: Disable the S7-PLCSIM Virtual Switch binding on the network adapter used by the affected instance. This prevents the adapter from entering an external communication mode.
- Restrict Multicast Traffic: Implement network controls to restrict multicast traffic on the specific segment hosting the SIMATIC S7-PLCSIM Advanced host.
For broader protection, Siemens recommends following their operational guidelines for Industrial Security and protecting all network access to devices with appropriate mechanisms.
