CVE-2025-50109 Details
Description
Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to another control sphere.
A vulnerability exists in Emerson ValveLink products, including ValveLink SOLO, DTM, PRM, and SNAP-ON, all versions prior to 14.0. These products store sensitive information in cleartext within a resource that may be accessible to another control sphere, potentially allowing unauthorized access to sensitive data.
Users are advised to update their ValveLink software to version 14.0 or later. The upgrade can be downloaded from the Emerson website. For more information, see the associated Emerson security notification.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 11, 2025CISA-ADP
Assessed Jul 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-189-01 | [email protected] | AdvisoryBundleRemedy |
| https://www.emerson.com/en-us/support/security-notifications | [email protected] | AdvisoryVendor |
| https://www.emerson.com/en-us/support/software-downloads-drivers | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-316 | Cleartext Storage of Sensitive Information in Memory | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Emerson ValveLink SOLO | < 14.0 |
CPE
Remediation
| |
| Emerson ValveLink DTM | All versions |
CPE
Remediation
| |
| Emerson ValveLink PRM | All versions |
CPE
Remediation
| |
| Emerson ValveLink SNAP-ON | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 11, 2025 | New CVE Received | [email protected] |
Volerion