CVE-2025-53703

7.5

DuraComm · SPM-500 DP-10iN-100-MU

DuraComm SPM-500 DP-10iN-100-MU devices transmit sensitive data in cleartext, allowing unauthenticated attackers to intercept information over the network.

Executive summary

The DuraComm SPM-500 DP-10iN-100-MU is vulnerable to cleartext data transmission, creating a high risk of sensitive information interception by unauthorized actors.

Vulnerability

This flaw, categorized as CWE-319, involves the transmission of sensitive data over an unencrypted channel. The vulnerability is exploitable by an unauthenticated remote attacker who can intercept network traffic to capture sensitive credentials or operational data.

Business impact

The lack of encryption for sensitive data transmissions poses a significant risk to organizational security and data privacy. Attackers capable of monitoring network traffic can harvest sensitive information, potentially leading to unauthorized access, operational disruption, or further compromise of the internal network infrastructure. With a CVSS score of 7.5, this high-severity vulnerability necessitates prompt remediation to prevent data leakage.

Remediation

Immediate Action: Update the affected DuraComm SPM-500 DP-10iN-100-MU units to firmware version 4.10A by contacting the vendor directly through their official website.

Proactive Monitoring: Monitor network traffic for unusual patterns or attempts to sniff data packets originating from or destined for the identified DuraComm devices.

Compensating Controls: Deploy the devices within a segmented, isolated management network or behind a secure VPN gateway to restrict access and encrypt traffic at the network layer until firmware updates are applied.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the high impact of cleartext credential and data exposure, administrators must prioritize the acquisition and installation of firmware version 4.10A. Until the update is deployed, ensure that affected devices are removed from public-facing segments and placed inside restricted network zones to minimize exposure to potential interception attacks.

More DuraComm CVEs

Sources

Originally found and disclosed by Brandon Vincent of Arizona Public Service reported these vulnerabilities to CISA., per the CVE Program record.