OPCFoundation OPC UA LocalDiscoveryServer (LDS)

Summary

A vulnerability (CVE-2026-77477) has been identified in OPCFoundation OPC UA LocalDiscoveryServer (LDS) installers versions prior to 1.04.420. Successful exploitation could allow an attacker to take control of a high-privilege terminal during installation and execute arbitrary commands.

IFF Assessment

FOE

This vulnerability allows attackers to gain elevated privileges and execute arbitrary commands, posing a direct threat to system security.

Severity

7.8 High (AI Estimated)

The CVSS v3 score of 4.6 is listed in the article, but this refers to a specific metric (Execution with Unnecessary Privileges). Considering the ability to 'run arbitrary commands' with high privileges during installation, an estimated CVSS score of 7.8 (High) is more representative of the potential impact.

Defender Context

Defenders should prioritize patching or updating OPCFoundation OPC UA LocalDiscoveryServer (LDS) installations to version 1.04.420 or later. This vulnerability impacts critical infrastructure sectors, highlighting the importance of timely patching in OT environments where attackers could gain significant control during software setup.

Read Full Story →