CVE-2024-10085
Received Received - Intake

OPC UA Platform Denial of Service via Resource Exhaustion

Vulnerability report for CVE-2024-10085, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Schneider Electric SE

Description

CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large number of OPC UA requests are sent to the platform.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
schneider_electric ecostruxure_opc_ua_server_expert to sv2.01_sp3 (exc)
schneider_electric ecostruxure_modicon_communication_server *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2024-10085 is a resource allocation flaw (CWE-770) in Schneider Electric's OPC UA servers. It allows denial of service when excessive requests overwhelm the system, disrupting real-time data from Modicon controllers.

Detection Guidance

Monitor for unusual spikes in OPC UA request traffic to Schneider Electric's EcoStruxure OPC UA Server Expert or Modicon Communication Server. Check server logs for excessive connection attempts or failed authentication events. Use network monitoring tools to detect abnormal data processing loads.

Impact Analysis

This vulnerability could cause system outages, disrupting industrial processes that rely on OPC UA communication. It may lead to loss of real-time data from Modicon controllers, affecting operational continuity.

Mitigation Strategies

Apply the patch for EcoStruxure OPC UA Server Expert (SV2.01 SP3) if affected. For both products, disable anonymous authentication and enforce user authentication. Configure secure communication policies and limit network exposure. Isolate affected systems and restrict physical access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-10085. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart