CVE-2026-54429
SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens SIMATIC S7-PLCSIM Advanced are affected: SIMATIC S7-PLCSIM Advanced vers:all/* (CVE-2026-54429) CVSS Vendor Equipment Vulnerabilities v3 7.4 Siemens Siemens SIMATIC S7-PLCSIM Advanced Allocation of Resources Without Limits or Throttling Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
EPSS 0.22% · 11.9th percentile
Risk Scores
Timeline
- Jul 14, 2026 EPSS Score
- Jul 14, 2026 CVE Published
- Jul 15, 2026 Coalition ESS Score
- Jul 15, 2026 CVE Updated
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03 advisory
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-03.json advisory
- https://www.cve.org/CVERecord?id=CVE-2026-54429 technical
- https://cwe.mitre.org/data/definitions/770.html technical
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H technical