← All Advisories

Adjacent Unauthenticated Attacker Can Exhaust the Advantech EKI-1242EIMS OPC UA Session Pool by Opening Multiple Anonymous Connections

Last refreshed2026-09-29

Status: NEW  |  Advisory ID: CVE-2026-73175

Key Details

CVECVE-2026-73175
CVSS Score / Version7.1 (High) / CVSS v4.0
Updated2026-09-23
Classified asCWE-400 (Uncontrolled Resource Consumption)

What to Know

Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust the server session pool and cause a complete denial of service to all legitimate OPC UA clients by opening multiple anonymous sessions.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-73175
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-73175