Impact
The vulnerability arises from insufficient protection of stored credentials in the Remote I/O Coupler Unit (Server Type) CPSN‑MCB271. Because credentials are not secured, an attacker who exploits this flaw can retrieve sensitive backup files, potentially exposing confidential information. This weakness corresponds to CWE‑522 and can lead to unauthorized data disclosure.
Affected Systems
The affected product is the Contec Co., Ltd. Remote I/O Coupler Unit (Server Type) CPSN‑MCB271 series, with all firmware revisions matching the CPSN‑MCB271 pattern. No specific firmware revisions were listed, so all current models may be vulnerable until patched.
Risk and Exploitability
The CVSS score is 8.2, indicating high severity. The EPSS score is < 1%, indicating a very low likelihood of exploitation at present; however, the lack of KEV listing suggests no widespread exploitation yet; nevertheless, the vulnerability could be leveraged by an adversary with network or physical access to the device. The attacker would need to access the backup file storage or exploit credential retrieval to restore sensitive data. The risk is therefore significant, warranting timely remediation.
OpenCVE Enrichment