Description
An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the event monitored‑item queue resize handling of Systerel S2OPC version 1.7.3 can be triggered by a remote attacker to force the queue to resize in a way that consumes excessive system resources, potentially rendering the OPC UA service unusable. The weakness arises from insufficient input validation during the resize operation, leading to uncontrolled resource consumption as specified by CWE‑400.

Affected Systems

Systerel S2OPC 1.7.3 is the only version documented as affected in the advisory; no other vendors or product versions are known to be impacted.

Risk and Exploitability

The EPSS score indicates a very low probability of exploitation (<1%), and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits. The CVSS score of 7.5 reflects a high severity due to the impact on availability. Attackers would need to send crafted OPC UA messages that trigger the monitored‑item queue to resize, implying the attack can be performed remotely against any exposed S2OPC instance without additional network traversal steps.

Generated by OpenCVE AI on August 6, 2026 at 15:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched release of Systerel S2OPC that corrects the monitored‑item queue resize flaw.
  • If an upgrade is not immediately possible, restrict OPC UA access to trusted IP ranges and apply network rate limiting to mitigate excessive queue creation attempts.
  • Enable monitoring of CPU and memory usage on the S2OPC process and configure alerts for abnormal consumption patterns that may indicate an attempted denial of service attack.

Generated by OpenCVE AI on August 6, 2026 at 15:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Event Monitored‑Item Queue Resize in Systerel S2OPC 1.7.3

Thu, 06 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Event Monitored‑Item Queue Resize in Systerel S2OPC 1.7.3
Weaknesses CWE-400

Thu, 06 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Systerel
Systerel s2opc
Vendors & Products Systerel
Systerel s2opc

Wed, 05 Aug 2026 23:30:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-06T12:28:47.598Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67872

cve-icon Vulnrichment

Updated: 2026-08-06T12:27:05.005Z

cve-icon NVD

Status : Received

Published: 2026-08-06T00:16:54.267

Modified: 2026-08-06T13:18:23.413

Link: CVE-2026-67872

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T15:15:12Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption