Executive brief
A denial-of-service vulnerability exists in the OPC-UA Server component of the ABB PPT30 operating system, which is used in industrial automation environments. An attacker can exploit this flaw over the network without needing any login credentials to crash the service or make it unresponsive. This can permanently prevent operators from monitoring or controlling industrial processes, potentially leading to significant operational downtime.
Technical details
The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) within the OPC-UA Server of the ABB PPT30 Operating System. It stems from a failure to properly limit or throttle resource consumption, which can be triggered by an unauthenticated attacker via the network. Successful exploitation allows the attacker to exhaust system resources, leading to a permanent denial-of-service (DoS) that prevents legitimate users from interacting with the service. The issue is addressed in PPT30 Operating System version 1.8.0.
Affected products
- ABB PPT30 Operating System before 1.8.0
Timeline
- 2026-05-26: advisory: Initial NVD publication and ABB advisory release