216.73.217.22

CVE-2025-11492

· Published 16/10/2025 19:15 · Modified 16/10/2025 19:15

Labels: CVE-2025-11492 2025-10-167d616e1a-3288-43b1-a0dd-0a65d3e70a49CVE-2025-11492CWE-319

Essential information

Published
16/10/2025 19:15
Modified
16/10/2025 19:15
Author
Creator
CVSS
9.6 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic. Additionally, the encryption method used to obfuscate some communications over the HTTP channel is updated in the Automate 2025.9 patch to enforce HTTPS for all agent communications.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
7d616e1a-3288-43b1-a0dd-0a65d3e70a49
NVD
View on NVD

Affected products (CPE)

ProductCPE
connectwise / automate cpe:2.3:a:connectwise:automate:*:*:*:*:*:*:*:*
connectwise / automate cpe:2.3:a:connectwise:automate:2025.9:*:*:*:*:*:*:*

References