Impact
The iRM-IEI Remote Management software has a missing authentication weakness that allows unauthenticated attackers to exploit a specific functionality and retrieve only partially exposed system configuration data. This exposure does not provide direct code execution or full system control but can reveal sensitive operational settings that may aid in planning further attacks against the target. The vulnerability is classified as a high‑severity Remote Information Disclosure with a CVSS score of 7.9.
Affected Systems
The affected product is the IEI Integration Corp iRM-TSi410X remote‑management controller. No specific version information was provided, so any firmware or software build of the iRM‑TSi410X that includes the unpatched Remote Management component is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.9 indicates that exploitation carries significant risk. Because authentication is not required, any attacker who can reach the remote‑management endpoint—via the public or internal network—can trigger the flaw with little effort. Although the EPSS score is not available, the lack of a known exploitation instance in the CISA KEV catalog means the vulnerability may be actively used but has not yet been widely documented. The combination of trivial access requirements and the ability to glean configuration data makes this a notable threat, especially for devices exposed directly to the internet or to untrusted networks.
OpenCVE Enrichment