ZeroHour

CVE-2026-73175

niche

Session-Pool Exhaustion DoS in Advantech EKI-1242EIMS OPC UA Gateway

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-73175 is an uncontrolled resource consumption flaw (CWE-400) in the OPC UA gateway component of the Advantech EKI-1242EIMS industrial gateway, confirmed in firmware version V1.06.01. An adjacent (same network segment) unauthenticated attacker can open multiple anonymous OPC UA sessions, exhausting the device's server session pool. Once the pool is exhausted, all legitimate OPC UA clients are denied service, resulting in a complete availability impact with no confidentiality or integrity impact (CVSS 4.0: 7.1 High). Operators of EKI-1242EIMS gateways in industrial and OT networks are affected, particularly where flat or poorly segmented networks allow adjacent devices to reach the OPC UA service. No public proof-of-concept is known, the flaw is not in CISA KEV, and there is no evidence of exploitation in the wild.

What to do: Check the installed firmware version on EKI-1242EIMS units and upgrade to a fixed release from Advantech as soon as one is published (no fixed version is identified in the advisory). Until patching, restrict access to the gateway's OPC UA interface to trusted clients on the OT network segment, disable or limit anonymous sessions where the configuration allows, and segment the network so unauthenticated adjacent devices cannot reach the device. Monitor for abnormal session creation or gateway unavailability.

Affected
Advantech EKI-1242EIMS (OPC UA gateway component)Firmware V1.06.01 confirmed affected; no other version ranges specified in the advisory
Estimated exposure
nichelikely low thousands of deployed units worldwide (no public install counts) — The EKI-1242EIMS is a niche single-purpose industrial Modbus-to-OPC UA gateway with no public install-base or internet-exposure scan counts, so the order of magnitude is inferred from typical deployment volumes of specialized OT protocol…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust the server session pool and cause a complete denial of service to all legitimate OPC UA clients by opening multiple anonymous sessions.

Weakness
CWE-400
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.