CVE-2026-16731

OMICRON electronics GmbH · StationScout

A timing discrepancy vulnerability in OMICRON StationScout versions prior to 3.05 may allow for unauthorized information disclosure or system manipulation.

Executive summary

An observable timing discrepancy in OMICRON StationScout versions before 3.05 poses a high-severity risk to system security and data integrity.

Vulnerability

This is a timing discrepancy vulnerability (CWE-208) that can be exploited by an unauthenticated attacker over the network. The vulnerability impacts the confidentiality and integrity of the system.

Business impact

Successful exploitation could result in full system compromise, including unauthorized access to sensitive operational data. The CVSS score of 8.3 reflects the high risk of this vulnerability, which could lead to significant operational disruptions in industrial or utility environments.

Remediation

Immediate Action: Upgrade OMICRON StationScout to version 3.05 or later as specified by the vendor advisory.

Proactive Monitoring: Monitor system logs for anomalous timing patterns or repeated failed access attempts that may indicate probing for timing discrepancies.

Compensating Controls: Isolate the affected systems from external networks and utilize secure gateways to restrict access to authorized personnel only.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The vulnerability presents a substantial risk to critical infrastructure components. It is imperative that operators schedule maintenance windows to apply the version 3.05 update as soon as possible to neutralize the risk of exploitation.