← Back to home
ICSA-26-209-03  ·  Published 2026-07-28  ·  View on CISA ICS-CERT ↗

Siemens SIMATIC S7-PLCSIM Advanced

CVSS 7.4 HIGH

Risk Summary

SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.

CVEs (1)

Remediations

  • Disable the S7-PLCSIM Virtual Switch binding on the network adapter used by the affected instance. This prevents the adapter from entering an external communication mode and removes the attack vector entirely. (see SIMATIC S7-PLCSIM Advanced Function Manual V8.0, 11/2025 Section 5.3 and Section 6.1.2.3; and SIMATIC S7-PLCSIM Advanced Function Manual API V8.0, 11/2025 Section 7.2)
  • Restrict multicast traffic on the network segment hosting the SIMATIC S7-PLCSIM Advanced host.
  • Use 'Softbus' / 'PLCSIM' network mode. This mode does not accept any packets from the network. This mode is a default network mode. (see SIMATIC S7-PLCSIM Advanced Function Manual V8.0, 11/2025 Section 5.0 and Section 5.1; and SIMATIC S7-PLCSIM Advanced Function Manual API V8.0, 11/2025 Section 7.2)
  • Currently no fix is available

Affected Vendors

Siemens

Affected Products (1)

Siemens · SIMATIC S7-PLCSIM Advanced vers:all/*

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more