iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software and the server, in plaintext without authentication or encryption. An attacker with network access can intercept sensitive information (such as credentials, keylogger data, and personally identifiable information) and tamper with traffic. This allows both unauthorized disclosure and modification of data, including issuing arbitrary commands to client agents.
Fixes

Solution

The vendor was unresponsive and did not answer to our communication attempts. Therefore, a patch is not available for these security issues. End users of this product should contact the vendor and demand a patch.


Workaround

No workaround given by the vendor.

References
History

Thu, 25 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 25 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Description iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software and the server, in plaintext without authentication or encryption. An attacker with network access can intercept sensitive information (such as credentials, keylogger data, and personally identifiable information) and tamper with traffic. This allows both unauthorized disclosure and modification of data, including issuing arbitrary commands to client agents.
Title Unencrypted and Unauthenticated Communication Allows Data Exposure and Manipulation in iMonitor EAM
Weaknesses CWE-319
References

cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published:

Updated: 2025-09-25T18:56:01.197Z

Reserved: 2025-09-16T07:44:29.591Z

Link: CVE-2025-10540

cve-icon Vulnrichment

Updated: 2025-09-25T18:55:57.361Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-25T14:15:42.203

Modified: 2025-09-26T14:32:53.583

Link: CVE-2025-10540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.