OPCFoundation OPC UA LocalDiscoveryServer (LDS)

MonitorCVSS 4.6ICS-CERT ICSA-26-246-01Sep 3, 2026
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionRequired
Summary

OPC UA LocalDiscoveryServer (LDS) Installers before version 1.04.420 contain a privilege escalation vulnerability during the installation process. An attacker with local access during installation could exploit insufficient privilege handling to execute arbitrary commands with elevated privileges, potentially gaining control of the system. The vulnerability requires local access and user interaction during the installation phase.

What this means
What could happen
An attacker with local access to a system during OPC UA LDS installation could execute arbitrary commands with elevated privileges, potentially compromising the integrity of the system and any connected industrial devices.
Who's at risk
Organizations using OPC UA LocalDiscoveryServer (LDS) for integrating SCADA systems, PLCs, and industrial devices should prioritize this. This affects manufacturers and operators of automation equipment that rely on OPC UA for real-time data exchange and device discovery in industrial networks.
How it could be exploited
An attacker with local access to a system running the vulnerable OPC UA LDS installer could exploit insufficient privilege handling during the installation process to inject and execute arbitrary commands with high-privilege access. This requires the attacker to be present or able to interact with the installation session.
Prerequisites
  • Local access to the system during OPC UA LDS installation
  • Ability to interact with the installation process (user interaction context)
  • Low privilege account sufficient to trigger the vulnerability
Local attack requiredRequires low privilegesInstallation-time vulnerabilityRequires user interaction
Affected products (1)
ProductAffected VersionsFix Status
UA-LDS-Installers<1.04.420No fix yet
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate OPC UA LDS Installers to version 1.04.420 or later
API: /api/v1/advisories/24c4acc8-1d20-4bdf-a0c4-d6709b532998

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

OPCFoundation OPC UA LocalDiscoveryServer (LDS) | CVSS 4.6 - OTPulse