Junglewise Threat Intelligence

CVE-2026-73175: Advantech EKI-1242 denial of service in OPC UA gateway

CVE-2026-73175 · Severity: info · CVSS 7.1 · Published 2026-09-16

Executive brief

Advantech EKI-1242 industrial gateway devices contain a vulnerability in their OPC UA (a widely-used industrial automation protocol) component that allows an adjacent attacker to exhaust server resources by opening many anonymous sessions. An attacker can exploit this to completely block all legitimate OPC UA clients from connecting, disrupting critical industrial operations and control systems that depend on this gateway.

Technical details

The OPC UA gateway component in the Advantech EKI-1242 series does not enforce proper session limits or authentication controls on anonymous session creation, leading to an uncontrolled resource consumption vulnerability (CWE-400). An adjacent, unauthenticated attacker can open multiple anonymous sessions to exhaust the server's session pool, preventing legitimate OPC UA clients from establishing connections. The attack requires network adjacency (e.g., on the same subnet) but no authentication or user interaction. This results in a complete denial of service to all OPC UA functionality. The vendor released firmware version 2.00.01 to address this issue.

Affected products

  • Advantech EKI-1242EIMS V1.06.01
  • Advantech EKI-1242IEIMS V1.06.01

Timeline

  • 2026-09-16: disclosed: CVE-2026-73175 published by Nozomi Networks Labs
  • 2026-09-04: patched: Advantech security advisory issued; firmware version 2.00.01 available

References

Related threats