Impact
A vulnerability in Siemens SIMATIC S7-PLCSIM Advanced allows an unauthenticated attacker on the local network to send high‑volume multicast traffic that exhausts application memory, causing the software to become unresponsive and requiring a manual restart. The exploit does not affect project data and requires a pre‑existing project configuration at the target instance. This flaw represents a classic resource‑exhaustion issue (CWE‑770).
Affected Systems
Siemens SIMATIC S7-PLCSIM Advanced, all versions.
Risk and Exploitability
The CVSS score of 6.0 indicates moderate severity, while the EPSS score of less than 1% shows a very low exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. An attacker would need local network access to flood multicast traffic; no authentication is required, and the failure mode is a denial of service affecting only the targeted application. Given the low exploitation likelihood, the overall risk is moderate but still significant for environments relying on uninterrupted PLC simulation.
OpenCVE Enrichment