CVEFinder.io

CVE-2025-11492

β›” critical
πŸ” Scan for this CVE
Summary

In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic. Additionally, the encryption method used to obfuscate some communications over the HTTP channel is updated in the Automate 2025.9 patch to enforce HTTPS for all agent communications.

CVSS Score
9.6
Critical
EPSS Score
0.0
Exploit Probability
Published Date
2025-10-16
First Seen: 2026-01-05
πŸ“Š Relative Risk Intelligence

This CVE is Very High Risk - more severe than 90.2% of all 360,673 vulnerabilities in our database.

#35,430
Top 10% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: Oct 17, 2025
πŸ” Exploitation Status
None
No known exploits
βš™οΈ Automatable
NO
Requires human interaction
πŸ’₯ Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2025-10-29
CVSS Vector 3.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE IDs (Weakness Types)

πŸ“¦ Affected Products 1

πŸ”— References 1

πŸ”— Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-9089 ⚠️ high 8.8 0.3 The ConnectWise Automateβ„’ Agent does not fully verify the authenticity of components obtained during plugin loading an... 2026-05-21
CVE-2025-11493 ⚠️ high 8.8 0.0 The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updat... 2025-10-16
CVE-2023-47256 πŸ”Ά medium 5.5 0.1 ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of ... 2024-02-01
CVE-2023-47257 ⚠️ high 8.1 5.0 ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted... 2024-02-01
CVE-2023-23126 πŸ”Ά medium 6.1 0.3 Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users... 2023-02-01
CVE-2023-23130 πŸ”Ά medium 5.9 0.2 Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext... 2023-02-01
These CVEs affect the same products