Executive brief
iRM-IEI Remote Management is a tool used for managing industrial computing hardware remotely. A security flaw allows unauthorized individuals to access parts of the system's configuration without logging in. This could expose sensitive setup details that might be used to plan further attacks against the infrastructure.
Technical details
A missing authentication vulnerability (CWE-306) exists in IEI Integration Corp's iRM-IEI Remote Management, specifically affecting the iRM-TSi410X product. The flaw allows a remote, unauthenticated attacker to access specific functional endpoints that should be protected. By exploiting this, an attacker can retrieve partial system configuration data. This information disclosure can facilitate reconnaissance for more complex attacks. The issue is resolved in version v1.4.19.
Affected products
- IEI Integration Corp iRM-TSi410X before v1.4.19
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory
- 2026-06-12: patched: Fixed in version v1.4.19