CVE-2025-46358 Details
Description
Emerson ValveLink products do not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
A vulnerability exists in Emerson ValveLink products due to improper implementation or absence of protective measures against targeted attacks. This issue affects ValveLink SOLO, DTM, PRM, and SNAP-ON, all versions prior to 14.0. The vulnerability could allow an attacker to read sensitive information stored in cleartext, manipulate parameters, and execute unauthorized code.
Users are advised to update to ValveLink 14.0 or later. The update is available on the Emerson website. For more information, consult the Emerson security notification.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 11, 2025CISA-ADP
Assessed Jul 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-189-01 | [email protected] | AdvisoryBundleRemedy |
| https://www.emerson.com/en-us/support/security-notifications | [email protected] | AdvisoryVendor |
| https://www.emerson.com/en-us/support/software-downloads-drivers | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-693 | Protection Mechanism Failure | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Emerson ValveLink SOLO | < 14.0 |
CPE
Remediation
| |
| Emerson ValveLink DTM | All versions |
CPE
Remediation
| |
| Emerson ValveLink PRM | All versions |
CPE
Remediation
| |
| Emerson ValveLink SNAP-ON | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 11, 2025 | New CVE Received | [email protected] |
Volerion