Description
CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large number of OPC UA requests are sent to the platform.
Published: 2026-09-01
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Fix
AI Analysis

Impact

A flaw in Schneider Electric’s EcoStruxure™ OPC UA Server allows unlimited allocation of resources when a large volume of OPC UA requests is received. The vulnerability, classified as CWE‑770, means that attackers can flood the server with requests, exhausting memory or processing capacity and causing the platform to become unresponsive, thereby disrupting availability for legitimate users.

Affected Systems

Schneider Electric’s EcoStruxure™ Modicon Communication Server and EcoStruxure™ OPC UA Server Expert are affected. No specific version numbers are listed in the advisory, so all current and older releases are assumed vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered simply by sending a large volume of OPC UA requests over the network, the likely attack vector is remote; no authentication is required to submit traffic, making the exploit broadly feasible for any entity with network access to the OPC UA endpoint.

Generated by OpenCVE AI on September 1, 2026 at 15:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the security patch detailed in Schneider Electric’s security notice SEVD‑2025‑287‑01.
  • Configure network or server‑side rate limiting to throttle the number of OPC UA requests per unit time, reducing the chance of resource exhaustion.
  • Restrict OPC UA access to trusted IP addresses or disable unused ports to limit exposure to attackers.

Generated by OpenCVE AI on September 1, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Schneider-electric
Schneider-electric ecostruxure Modicon Communication Server
Schneider-electric ecostruxure Opc Ua Server Expert
Vendors & Products Schneider-electric
Schneider-electric ecostruxure Modicon Communication Server
Schneider-electric ecostruxure Opc Ua Server Expert

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unrestricted Resource Allocation Causing Denial of Service in Schneider Electric OPC UA Server
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large number of OPC UA requests are sent to the platform.
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Schneider-electric Ecostruxure Modicon Communication Server Ecostruxure Opc Ua Server Expert
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2026-09-01T15:42:52.599Z

Reserved: 2024-10-17T14:50:40.481Z

Link: CVE-2024-10085

cve-icon Vulnrichment

Updated: 2026-09-01T15:42:47.969Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T14:17:22.620

Modified: 2026-09-01T20:52:39.973

Link: CVE-2024-10085

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T16:28:12Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling