PT-2025-39376 · Unknown · Imonitor Eam
Published
2025-09-25
·
Updated
2025-09-25
·
CVE-2025-10540
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
iMonitor EAM version 9.6394
Description
The software transmits communication between the EAM client agent and the EAM server, and between the EAM monitor management software and the server, in plaintext without authentication or encryption. An attacker with network access can intercept sensitive information, such as credentials, keylogger data, and personally identifiable information, and tamper with traffic. This allows for unauthorized disclosure and modification of data, including the potential to issue arbitrary commands to client agents.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imonitor Eam