The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk where an on-path attacker could perform a man-in-the-middle attack and substitute malicious files for legitimate ones by impersonating a legitimate server. This risk is mitigated when HTTPS is enforced and is related to CVE-2025-11492.
oryginał ENCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HConnectwise Automate
APPConnectwise< 2025.9
Powiązane podatności
ConnectWise Automate Agent – nieszyfrowana komunikacja HTTP podatna na MITM
XXE w ConnectWise Automate umożliwia przejęcie kontroli nad systemem
ConnectWise Automate — pominięcie uwierzytelnienia (Auth Bypass)
ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectW...
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution v...