Description
Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust the server session pool and cause a complete denial of service to all legitimate OPC UA clients by opening multiple anonymous sessions.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an uncontrolled resource consumption flaw in the OPC UA gateway component of Advantech's EKI-1242EIMS firmware V1.06.01. An unauthenticated, adjacent attacker can open multiple anonymous sessions, which exhausts the server’s session pool and blocks all legitimate OPC UA clients from connecting. The result is a complete denial of service to the gateway and any systems that depend on it for OPC UA traffic. This flaw is identified as CWE‑400.

Affected Systems

The affected systems are Advantech EKI‑1242EIMS and EKI‑1242IEIMS gateways running firmware version V1.06.01. The flaw resides in the gateway’s OPC UA server, which is used to broker communication with industrial control equipment.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity with potential for service disruption. The EPSS score of less than 1% suggests a very low probability of exploitation at this time, and the catalog does not list the vulnerability as a known exploited vulnerability. The likely attack vector is local or adjacent, where an unauthenticated attacker can connect to the OPC UA endpoint. Because the flaw does not require authentication, an attacker who can communicate on the network segment that hosts the gateway can trigger the denial of service.

Generated by OpenCVE AI on September 18, 2026 at 02:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by Advantech for the EKI‑1242EIMS and EKI‑1242IEIMS gateways that fixes the session‑pool exhaustion issue. The vendor’s security advisory provides the update package and installation instructions.
  • Disable or restrict anonymous OPC UA session connections in the gateway’s configuration to limit the number of sessions that can be created without authentication.
  • Configure network firewalls or OPC UA server settings to restrict access to the gateway’s OPC UA port to trusted IP addresses only, and consider implementing rate limiting on session creation to prevent resource exhaustion.

Generated by OpenCVE AI on September 18, 2026 at 02:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Title OPC UA Gateway Denial of Service via Uncontrolled Resource Consumption

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Advantech
Advantech eki-1242eims
Advantech eki-1242ieims
Vendors & Products Advantech
Advantech eki-1242eims
Advantech eki-1242ieims

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust the server session pool and cause a complete denial of service to all legitimate OPC UA clients by opening multiple anonymous sessions.
Weaknesses CWE-400
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Advantech Eki-1242eims Eki-1242ieims
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-09-17T18:57:57.089Z

Reserved: 2026-08-11T09:36:40.350Z

Link: CVE-2026-73175

cve-icon Vulnrichment

Updated: 2026-09-17T18:57:51.715Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T13:18:06.017

Modified: 2026-09-23T11:10:00.187

Link: CVE-2026-73175

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:00:09Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption