Impact
A flaw in Schneider Electric’s EcoStruxure™ OPC UA Server allows unlimited allocation of resources when a large volume of OPC UA requests is received. The vulnerability, classified as CWE‑770, means that attackers can flood the server with requests, exhausting memory or processing capacity and causing the platform to become unresponsive, thereby disrupting availability for legitimate users.
Affected Systems
Schneider Electric’s EcoStruxure™ Modicon Communication Server and EcoStruxure™ OPC UA Server Expert are affected. No specific version numbers are listed in the advisory, so all current and older releases are assumed vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered simply by sending a large volume of OPC UA requests over the network, the likely attack vector is remote; no authentication is required to submit traffic, making the exploit broadly feasible for any entity with network access to the OPC UA endpoint.
OpenCVE Enrichment