VulnerabilitiesSep 28, 2026
One Packet Can Crash OT Servers in Industrial Sectors
Zero-day vulnerability in TDengine database allows remote attackers to crash OT servers.
Summary
A critical zero-day vulnerability has been discovered in the TDengine time-series database, posing a significant risk to industrial control systems (ICS) and operational technology (OT) environments. Exploiting this flaw requires sending a single malformed packet, which can lead to a complete server crash. The vulnerability affects TDengine deployments across various sectors, including industrial automation, energy, IoT, and automotive.
Indicators of Compromise
- cve — CVE-2024-22137
Entities
TDengine (product)time-series database (technology)OT (technology)IoT (technology)