IM
IronMonkey Threat Research
‹ Back to ICS Advisories

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

MEDIUM
CVSS 4.6
Date 2026-09-03T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-77477 4.6 medium
An attacker can intercept a high-privilege console window launched during installation of the LDS. The attacker must be able to launch an installer with elevated privileges and have access to the keyboard and display while the installation is taking place.

// Remediations (2)

Mitigation: OPCFoundation recommends users update to OPC UA LDS Installers 1.04.420 or later.
OPCFoundation recommends users update to OPC UA LDS Installers 1.04.420 or later.
Mitigation: For more information about this vulnerability and its mitigation, see the OPCFoundation security adv
For more information about this vulnerability and its mitigation, see the OPCFoundation security advisory.

// References