CVE-2025-46358: Emerson ValveLink Products Protection Mechanism Failure
Published Jul 10, 2025
·Updated
Emerson ValveLink products do not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Affected Software
4 affected components
Emerson ValveLink SOLO: All versions prior to ValveLink 14.0
Emerson ValveLink DTM: All versions prior to ValveLink 14.0
Emerson ValveLink PRM: All versions prior to ValveLink 14.0
Emerson ValveLink SNAP-ON: All versions prior to ValveLink 14.0
Remediation
Information
Emerson recommends users update their Valvelink software to ValveLink
14.0 or later. The upgrade can be downloaded from the Emerson website https://www.emerson.com/en-us/support/software-downloads-drivers .For more information see the associated Emerson security notification. https://www.emerson.com/en-us/support/security-notifications
Event History
Jul 10, 2025
Data Sourced
via ICS·11:41 PM
SeverityWeaknessAffected Software
CVE Published
via MITRE·11:41 PM
Data Sourced
via MITRE·11:41 PM
RemedyDescriptionSeverityWeakness
Jul 11, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-46358?
CVE-2025-46358 is rated as critical due to its potential for exploitation in directed attacks.
2
How do I fix CVE-2025-46358?
To remediate CVE-2025-46358, update to ValveLink version 14.0 or later.
3
Which Emerson ValveLink products are affected by CVE-2025-46358?
CVE-2025-46358 affects all versions of ValveLink SOLO, DTM, PRM, and SNAP-ON prior to ValveLink 14.0.
4
What kind of attacks does CVE-2025-46358 protect against?
CVE-2025-46358 is designed to protect against directed attacks that exploit inadequate protection mechanisms.
5
Is there a workaround for CVE-2025-46358?
No official workaround is available for CVE-2025-46358; upgrading to the latest software version is recommended.