ZeroHour

CVE-2024-10085

Resource Exhaustion DoS in Schneider Electric OPC UA Communication Platform

CVSS 4.0
8.2 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2024-10085 is an allocation-of-resources-without-limits flaw (CWE-770) in the OPC UA communication platform, with the advisory assigned through Schneider Electric's cybersecurity team ([email protected]). A remote, unauthenticated attacker can trigger it by sending a large volume of OPC UA requests to the platform, which allocates resources without throttling until the platform is exhausted. The impact is denial of service: the CVSS 4.0 vector (VA:H with all confidentiality/integrity metrics set to none) indicates high availability impact with no evidence of code execution or data compromise. Organizations running the affected Schneider Electric OPC UA communication platform in industrial environments are in scope, particularly where OPC UA endpoints are reachable from untrusted networks. No public proof-of-concept, CISA KEV listing, or notable exploitation activity is known, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Check the corresponding Schneider Electric security notification (SEVD) for the definitive list of affected products, versions, and fixed releases, and apply the vendor's update as soon as practical. In the meantime, restrict network access to OPC UA endpoints via firewalling and OT/IT segmentation, and monitor or rate-limit OPC UA client connections to blunt a request-flood DoS. Treat this as an availability risk only; there is no indication of code execution or data exposure.

Affected
Schneider Electric OPC UA communication platform
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large number of OPC UA requests are sent to the platform.

Weakness
CWE-770
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.