CVE-2026-73174
nicheCleartext Management Traffic Exposure in Advantech EKI-1242EIMS
Advantech's EKI-1242EIMS edge device transmits its edgserver management protocol data without encryption (CWE-319), as identified by Nozomi Networks Labs in firmware V1.06.01. A network-adjacent attacker can passively observe this traffic—no active exploitation, privileges, or user interaction are required. By sniffing the cleartext management traffic, the attacker recovers sensitive device identity information and network metadata, which can support reconnaissance and follow-on attacks against the OT environment. Any deployment running EKI-1242EIMS firmware V1.06.01 where management traffic crosses network segments an attacker can observe is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.
What to do: Check deployed EKI-1242EIMS units for firmware V1.06.01 and monitor the Advantech security advisory and product pages for a fixed firmware release before upgrading. Until a fix is available, limit exposure by segmenting management traffic away from attacker-reachable network segments, restricting L2 adjacency, and carrying edgserver traffic over an encrypted tunnel or out-of-band management network. Review network monitoring for any passive sniffing indicators on segments hosting these devices.
| Advantech EKI-1242EIMS (edgserver management protocol) | Firmware V1.06.01 (the only version named in the advisory; other versions not confirmed) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive observer to intercept management traffic and recover sensitive device identity and network metadata in cleartext.
- Weakness
- CWE-319
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.