Denial of Service Vulnerability in OPC UA Communication Platform from Schneider Electric
CVE-2024-10085

8.2HIGH

What is CVE-2024-10085?

A resource allocation vulnerability exists in Schneider Electric's OPC UA Communication Platform, which could lead to a denial of service. This vulnerability allows an attacker to overwhelm the platform by sending a high volume of OPC UA requests, potentially disrupting normal operations and impairing communication. The lack of throttling or limits on resource allocation makes this issue particularly concerning, as it opens the door for malicious actors to exploit the system's weaknesses.

Affected Version(s)

EcoStruxure™ Modicon Communication Server All versions

EcoStruxure™ OPC UA Server Expert Versions prior to SV2.01 SP3

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.