Junglewise Threat Intelligence

CVE-2024-10085: Schneider Electric OPC UA resource exhaustion denial of service

CVE-2024-10085 · Severity: info · Published 2026-09-01

Vendors: Schneider Electric.

Executive brief

OPC UA is a communication protocol widely used in industrial control systems and manufacturing environments to exchange data between devices and software. A vulnerability allows attackers to send a large volume of requests that consume platform resources without restriction, potentially disrupting production systems and preventing legitimate communication.

Technical details

This is an allocation-of-resources-without-limits vulnerability (CWE-770) in the OPC UA communication platform. An attacker can trigger a denial of service condition by sending a large number of OPC UA requests that exhaust available resources on the platform without throttling or rate limiting. The attack requires network access to the OPC UA service port. The impact is unavailability of the OPC UA communication infrastructure, which may disrupt industrial operations dependent on the platform.

Affected products

  • Schneider Electric OPC UA Communication Platform

Timeline

  • 2026-09-01: disclosed

References