In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic. Additionally, the encryption method used to obfuscate some communications over the HTTP channel is updated in the Automate 2025.9 patch to enforce HTTPS for all agent communications.
When ConnectWise Automate Agent uses HTTP protocol, all traffic between the agent and management server is transmitted without proper transport encryption. An attacker with a privileged network position (man-in-the-middle, on-path) in a local or network segment can intercept transmitted data, modify commands or server responses, and replay captured packets (replay attack). The previous obfuscation method used in the HTTP channel did not provide sufficient cryptographic protection. Automate 2025.9 patch enforces HTTPS for all agent communication.
An attacker can gain full control over the agent's communication with the management server, leading to disclosure of sensitive data (C:H), modification of transmitted commands and configurations (I:H), and potential disruption of availability of managed systems (A:H) — including the ability to execute arbitrary commands on managed endpoints.
ConnectWise Automate must be updated to version 2025.9 or later, which enforces HTTPS for all agent-to-server communication. Detailed information is available in the vendor's security bulletin: https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-2025.9-security-fix
ConnectWise Automate Agent in versions prior to Automate 2025.9, configured to communicate via HTTP protocol
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HConnectwise Automate
APPConnectwise< 2025.9
Related vulnerabilities
XXE w ConnectWise Automate umożliwia przejęcie kontroli nad systemem
ConnectWise Automate — pominięcie uwierzytelnienia (Auth Bypass)
ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectW...
The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, suc...
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution v...