CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-11492

CVSS 9.6v3.1pub. 2025-10-16upd. 2025-10-29

In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic. Additionally, the encryption method used to obfuscate some communications over the HTTP channel is updated in the Automate 2025.9 patch to enforce HTTPS for all agent communications.

🤖 AI Analysis
How it works

When ConnectWise Automate Agent uses HTTP protocol, all traffic between the agent and management server is transmitted without proper transport encryption. An attacker with a privileged network position (man-in-the-middle, on-path) in a local or network segment can intercept transmitted data, modify commands or server responses, and replay captured packets (replay attack). The previous obfuscation method used in the HTTP channel did not provide sufficient cryptographic protection. Automate 2025.9 patch enforces HTTPS for all agent communication.

Impact

An attacker can gain full control over the agent's communication with the management server, leading to disclosure of sensitive data (C:H), modification of transmitted commands and configurations (I:H), and potential disruption of availability of managed systems (A:H) — including the ability to execute arbitrary commands on managed endpoints.

Mitigation & patch

ConnectWise Automate must be updated to version 2025.9 or later, which enforces HTTPS for all agent-to-server communication. Detailed information is available in the vendor's security bulletin: https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-2025.9-security-fix

Who is affected

ConnectWise Automate Agent in versions prior to Automate 2025.9, configured to communicate via HTTP protocol

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Connectwise Automate

    APP
    Connectwise
    < 2025.9
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2021-35066CRITICAL9.8PL ✓same product

XXE w ConnectWise Automate umożliwia przejęcie kontroli nad systemem

CVE-2020-15027CRITICAL9.8PL ✓same product

ConnectWise Automate — pominięcie uwierzytelnienia (Auth Bypass)

CVE-2026-6066HIGH7.1same product

ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectW...

CVE-2025-11493HIGH8.8same product

The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, suc...

CVE-2023-47257HIGH8.1same product

ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution v...