CISA and Schneider Electric disclosed a critical vulnerability in the EcoStruxure OPC UA Server Expert and Modicon Communication Server products, which are widely deployed in commercial facilities, critical manufacturing, and energy sectors. The flaw, tracked as CVE-2024-10085, is an 'allocation of resources without limits or throttling' issue that allows remote attackers to cause a denial of service by sending a large number of OPC UA requests, potentially resulting in the loss of real-time process data from Modicon Controllers. The vulnerability has a CVSS v3.1 base score of 7.5 and a CVSS v4 base score of 8.2, indicating a high level of risk, and was reported by Jin Huang of ADLab of Venustech.
Schneider Electric has released a fix for the EcoStruxure OPC UA Server Expert in version SV2.01 SP3, which is available for download. For users unable to immediately apply the update, Schneider Electric recommends implementing specific mitigations to reduce the risk of exploitation. A permanent remediation plan is also being developed for all future versions of the Modicon Communication Server. CISA urges asset owners and operators in affected sectors to review the advisories and apply the recommended mitigations to protect against potential denial-of-service attacks targeting these critical industrial control systems.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Industrial Cyber reported that CISA had issued an ICS advisory concerning Schneider Electric vulnerabilities, reflecting public coverage of the advisory's release. The article does not clearly introduce a separate underlying real-world event beyond the advisory itself.
CISA released ICS advisory ICSA-25-301-01 covering vulnerabilities affecting Schneider Electric EcoStruxure. The advisory publicly documented the issue and associated security guidance for industrial control system defenders.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.