Uncontrolled Resource Consumption Vulnerability in Advantech EKI-1242EIMS Gateway
CVE-2026-73175

7.1HIGH

Key Information:

Vendor

Advantech

Vendor
CVE Published:
16 September 2026

What is CVE-2026-73175?

A vulnerability was discovered in the OPC UA gateway component of the Advantech EKI-1242EIMS device that allows adjacent unauthenticated attackers to exploit the server session pool. By opening multiple unauthorized sessions, attackers can deplete the session capacity, leading to denial of service for legitimate clients, which impedes their ability to establish necessary communications.

Affected Version(s)

EKI-1242EIMS 0 <= 1.06.01

EKI-1242IEIMS 0 <= 1.06.01

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Simone Bossi at Nozomi Networks
.