CVE-2025-11492 Details
Description
In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic. Additionally, the encryption method used to obfuscate some communications over the HTTP channel is updated in the Automate 2025.9 patch to enforce HTTPS for all agent communications.
A vulnerability exists in the ConnectWise Automate Agent due to the option to configure communications over HTTP instead of HTTPS. This flaw allows an on-path threat actor in a man-in-the-middle position to intercept, modify, or replay traffic between the agent and server. In addition, the encryption method used to obscure some communications over HTTP could be exploited to tamper with agent updates. The Automate 2025.9 patch addresses this issue by enforcing HTTPS for all agent communications. Partners with on-premises servers should also ensure TLS 1.2 is enforced for secure communications.
For on-premises environments, apply the 2025.9 release. Instructions for updating to the latest release can be found in the ConnectWise Automate Release Notes 2025.9.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-2025.9-security-fix | ConnectWise | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | ConnectWise |
Affected Products
| Product | Versions |
|---|---|
| connectwise automate | < 2025.9 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ConnectWise |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 29, 2025 | Initial Analysis | [email protected] |
| Oct 16, 2025 | New CVE Received | ConnectWise |