Impact
A flaw in the event monitored‑item queue resize handling of Systerel S2OPC version 1.7.3 can be triggered by a remote attacker to force the queue to resize in a way that consumes excessive system resources, potentially rendering the OPC UA service unusable. The weakness arises from insufficient input validation during the resize operation, leading to uncontrolled resource consumption as specified by CWE‑400.
Affected Systems
Systerel S2OPC 1.7.3 is the only version documented as affected in the advisory; no other vendors or product versions are known to be impacted.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation (<1%), and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits. The CVSS score of 7.5 reflects a high severity due to the impact on availability. Attackers would need to send crafted OPC UA messages that trigger the monitored‑item queue to resize, implying the attack can be performed remotely against any exposed S2OPC instance without additional network traversal steps.
OpenCVE Enrichment