iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software and the server, in plaintext without authentication or encryption. An attacker with network access can intercept sensitive information (such as credentials, keylogger data, and personally identifiable information) and tamper with traffic. This allows both unauthorized disclosure and modification of data, including issuing arbitrary commands to client agents.
References
History

Mon, 29 Sep 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Imonitor
Imonitor imonitor Eam
Vendors & Products Imonitor
Imonitor imonitor Eam

Thu, 25 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 25 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Description iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as well as between the EAM monitor management software and the server, in plaintext without authentication or encryption. An attacker with network access can intercept sensitive information (such as credentials, keylogger data, and personally identifiable information) and tamper with traffic. This allows both unauthorized disclosure and modification of data, including issuing arbitrary commands to client agents.
Title Unencrypted and Unauthenticated Communication Allows Data Exposure and Manipulation in iMonitor EAM
Weaknesses CWE-319
References

cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published:

Updated: 2025-09-25T18:56:01.197Z

Reserved: 2025-09-16T07:44:29.591Z

Link: CVE-2025-10540

cve-icon Vulnrichment

Updated: 2025-09-25T18:55:57.361Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-25T14:15:42.203

Modified: 2025-09-26T14:32:53.583

Link: CVE-2025-10540

cve-icon Redhat

No data.