Impact
A stored cross‑site scripting flaw exists in the Modbus transaction management interface of Advantech EKI‑1242EIMS firmware V1.06.01. An attacker who can authenticate to the interface can embed malicious script; when an administrator visits the page the script runs in their browser.
Affected Systems
Advantech EKI‑1242EIMS units running firmware version V1.06.01. The CNA also lists the EKI‑1242IEIMS product as affected, but the CVE description only specifies the firmware version for EKI‑1242EIMS. No other firmware or product versions are noted as affected.
Risk and Exploitability
The CVSS score of 6.3 classifies the vulnerability as moderate. The EPSS score of less than 1 % indicates a very low likelihood of exploitation, and the flaw is not listed in CISA’s KEV catalog. Exploitation requires a remote authenticated attacker, meaning the attacker must first obtain valid credentials or compromise a user account to use the flaw. The impact is limited to browser sessions of administrators who access the affected management page.
OpenCVE Enrichment