CVE-2026-73175: Advantech OPC UA gateway component of EKI-1242EIMS vulnerability
Published Sep 16, 2026
·Updated
Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust the server session pool and cause a complete denial of service to all legitimate OPC UA clients by opening multiple anonymous sessions.
Affected Software
1 affected component
Advantech OPC UA gateway component of EKI-1242EIMS=V1.06.01
Event History
Sep 16, 2026
CVE Published
via MITRE·01:02 PM
Data Sourced
via MITRE·01:02 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Advantech EKI-1242EIMS devices running firmware V1.06.01 are affected when their OPC UA gateway is reachable by an adjacent attacker.
2
Does exploitation require authentication or valid OPC UA credentials?
No. An adjacent attacker can exploit the issue without authentication by opening multiple anonymous OPC UA sessions.
3
What is the operational impact of a successful attack?
The attacker can exhaust the OPC UA server session pool, causing a complete denial of service for legitimate OPC UA clients.