CVE-2025-11493
The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk where an on-path attacker could perform a man-in-the-middle attack and substitute malicious files for legitimate ones by impersonating a legitimate server. This risk is mitigated when HTTPS is enforced and is related to CVE-2025-11492.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.22%
- CWE
- CWE-494
- Published
- 2025-10-16
- Last modified
- 2026-03-12
Affected products
- ConnectWise Automate
Weakness type
Related vulnerabilities
- CVE-2026-81052 — Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check...
- CVE-2026-79963 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-62654 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance...
- CVE-2026-85427 — MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthenticated MISSION_FILE
- CVE-2026-82021 — Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch Reference
- CVE-2026-21810 — HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and downloading code without integrity checking
- CVE-2026-65081 — NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker...
- CVE-2026-65097 — NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker...