CVE-2025-11493
The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk where an on-path attacker could perform a man-in-the-middle attack and substitute malicious files for legitimate ones by impersonating a legitimate server. This risk is mitigated when HTTPS is enforced and is related to CVE-2025-11492.
Vendor
Product
CWE
Yayın Tarihi
2025-10-16 19:15:32
Güncelleme
2025-10-29 19:28:11
Source Identifier
7d616e1a-3288-43b1-a0dd-0a65d3e70a49
KEV Date Added
-