Impact
The vulnerability allows a passive observer with network adjacency to intercept management traffic from Advantech EKI‑1242EIMS firmware V1.06.01 and recover device identity and network metadata in cleartext. Based on the description, it is inferred that the attacker could be physically or logically adjacent on the same network, passively monitoring traffic without requiring authentication or active exploitation. This results in unauthorized disclosure of sensitive information without interaction with the device.
Affected Systems
Devices affected are Advantech EKI‑1242EIMS running firmware V1.06.01. The EKI‑1242IEIMS variant is not mentioned as vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity impact, while the EPSS score of less than 1% shows a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would likely be physically or logically adjacent on the same network, passively monitoring traffic, and could gain valuable information without interacting with the device.
OpenCVE Enrichment