CVE-2024-10085
—Resource Exhaustion DoS in Schneider Electric OPC UA Communication Platform
CVE-2024-10085 is an allocation-of-resources-without-limits flaw (CWE-770) in the OPC UA communication platform, with the advisory assigned through Schneider Electric's cybersecurity team ([email protected]). A remote, unauthenticated attacker can trigger it by sending a large volume of OPC UA requests to the platform, which allocates resources without throttling until the platform is exhausted. The impact is denial of service: the CVSS 4.0 vector (VA:H with all confidentiality/integrity metrics set to none) indicates high availability impact with no evidence of code execution or data compromise. Organizations running the affected Schneider Electric OPC UA communication platform in industrial environments are in scope, particularly where OPC UA endpoints are reachable from untrusted networks. No public proof-of-concept, CISA KEV listing, or notable exploitation activity is known, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Check the corresponding Schneider Electric security notification (SEVD) for the definitive list of affected products, versions, and fixed releases, and apply the vendor's update as soon as practical. In the meantime, restrict network access to OPC UA endpoints via firewalling and OT/IT segmentation, and monitor or rate-limit OPC UA client connections to blunt a request-flood DoS. Treat this as an availability risk only; there is no indication of code execution or data exposure.
| Schneider Electric OPC UA communication platform | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large number of OPC UA requests are sent to the platform.
- Weakness
- CWE-770
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.