CVE-2026-73175: Advantech OPC UA gateway component of EKI-1242EIMS vulnerability

Published Sep 16, 2026
·
Updated

Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust the server session pool and cause a complete denial of service to all legitimate OPC UA clients by opening multiple anonymous sessions.

Affected Software

1 affected component
Advantech OPC UA gateway component of EKI-1242EIMS=V1.06.01

Event History

Sep 16, 2026
CVE Published
via MITRE·01:02 PM
Data Sourced
via MITRE·01:02 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Advantech EKI-1242EIMS devices running firmware V1.06.01 are affected when their OPC UA gateway is reachable by an adjacent attacker.

2

Does exploitation require authentication or valid OPC UA credentials?

No. An adjacent attacker can exploit the issue without authentication by opening multiple anonymous OPC UA sessions.

3

What is the operational impact of a successful attack?

The attacker can exhaust the OPC UA server session pool, causing a complete denial of service for legitimate OPC UA clients.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203