In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.
Conclusion & alert: CVE-2021-40142 is rated Moderate Risk (59.3/100): CVSS High severity, with medium exploitation likelihood (EPSS 2.56%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-20 | 2.38% | 2.56% | +0.18% |
| 2 | 2026-06-15 | 0.50% | 2.38% | +1.88% |
| 3 | 2026-03-15 | — | 0.50% | — |
Full EPSS history (23 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| opcfoundation | local_discover_server | < 1.04.402.463 | cpe:2.3:a:opcfoundation:local_discover_server:*:*:*:*:*:*:*:* |
| siemens | simatic_process_historian_opc_ua_server_firmware | < 2022 | cpe:2.3:o:siemens:simatic_process_historian_opc_ua_server_firmware:*:*:*:*:*:*:*:* |
| siemens | simatic_process_historian_opc_ua_server_firmware | 2022 | cpe:2.3:o:siemens:simatic_process_historian_opc_ua_server_firmware:2022:-:*:*:*:*:*:* |
| siemens | simatic_net_pc | 14 | cpe:2.3:a:siemens:simatic_net_pc:14:-:*:*:*:*:*:* |
| siemens | simatic_net_pc | 15 | cpe:2.3:a:siemens:simatic_net_pc:15:-:*:*:*:*:*:* |
| siemens | simatic_net_pc | 16 | cpe:2.3:a:siemens:simatic_net_pc:16:-:*:*:*:*:*:* |
| siemens | simatic_net_pc | 17 | cpe:2.3:a:siemens:simatic_net_pc:17:-:*:*:*:*:*:* |
| siemens | simatic_wincc | — | cpe:2.3:a:siemens:simatic_wincc:-:*:*:*:*:*:*:* |
| siemens | simatic_wincc_runtime | — | cpe:2.3:a:siemens:simatic_wincc_runtime:-:*:*:*:professional:*:*:* |
| siemens | simatic_wincc_unified_scada_runtime | — | cpe:2.3:a:siemens:simatic_wincc_unified_scada_runtime:-:*:*:*:*:*:*:* |
| siemens | telecontrol_server_basic | 3.0 | cpe:2.3:a:siemens:telecontrol_server_basic:3.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-321292.pdf | Patch Third Party Advisory |
| https://files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2021-40142.pdf | Patch Vendor Advisory |
| https://opcfoundation.org/security-bulletins/ | Vendor Advisory |