CVE-2025-11493
β οΈ highSummary
The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk where an on-path attacker could perform a man-in-the-middle attack and substitute malicious files for legitimate ones by impersonating a legitimate server. This risk is mitigated when HTTPS is enforced and is related to CVE-2025-11492.
CVSS Score
8.8
High
EPSS Score
0.0
Exploit Probability
Published Date
2025-10-16
First Seen: 2026-01-05
π Relative Risk Intelligence
This CVE is High Risk - more severe than 80.8% of all 360,673 vulnerabilities in our database.
#69,256
Top 25% most severe
Severity Percentile
π― CISA SSVC Assessment Updated: Oct 16, 2025
π Exploitation Status
None
No known exploits
βοΈ Automatable
NO
Requires human interaction
π₯ Technical Impact
Total
Complete system compromise possible
SSVC data provided by
CISA
Last Modified
2025-10-29
Source
NVD π
CVSS Vector 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE IDs (Weakness Types)