ZeroHour

CVE-2026-73174

niche

Cleartext Management Traffic Exposure in Advantech EKI-1242EIMS

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

Advantech's EKI-1242EIMS edge device transmits its edgserver management protocol data without encryption (CWE-319), as identified by Nozomi Networks Labs in firmware V1.06.01. A network-adjacent attacker can passively observe this traffic—no active exploitation, privileges, or user interaction are required. By sniffing the cleartext management traffic, the attacker recovers sensitive device identity information and network metadata, which can support reconnaissance and follow-on attacks against the OT environment. Any deployment running EKI-1242EIMS firmware V1.06.01 where management traffic crosses network segments an attacker can observe is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.

What to do: Check deployed EKI-1242EIMS units for firmware V1.06.01 and monitor the Advantech security advisory and product pages for a fixed firmware release before upgrading. Until a fix is available, limit exposure by segmenting management traffic away from attacker-reachable network segments, restricting L2 adjacency, and carrying edgserver traffic over an encrypted tunnel or out-of-band management network. Review network monitoring for any passive sniffing indicators on segments hosting these devices.

Affected
Advantech EKI-1242EIMS (edgserver management protocol)Firmware V1.06.01 (the only version named in the advisory; other versions not confirmed)
Estimated exposure
nichelikely thousands to low tens of thousands of devices worldwide across industrial sites (estimate) — No public scan or install-count data exists for this model; as a specialized Advantech industrial edge IoT/OT gateway typically deployed in small quantities per industrial facility, the population is plausibly in the thousands of units,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive observer to intercept management traffic and recover sensitive device identity and network metadata in cleartext.

Weakness
CWE-319
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.