Impact
An attacker can invoke critical REST API functions on the Contec Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* without authentication, allowing them to read I/O values or command outputs. The vulnerability is a Missing Authentication flaw (CWE-306) and is scored with a CVSS of 6.9, indicating moderate severity and potential impacts to confidentiality, integrity and availability.
Affected Systems
The affected product is Contec Co., Ltd.'s Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* - all models in the series are impacted, no specific firmware or software version is listed.
Risk and Exploitability
The EPSS score is 0.00201, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation yet; however, the CVSS of 6.9 reflects moderate risk. The flaw is exploitable remotely over the network via the exposed REST API with no authentication required. A remote attacker could potentially retrieve sensitive data or disrupt operation by manipulating I/O outputs.
OpenCVE Enrichment