CVE-2025-48496: Emerson ValveLink Products Uncontrolled Search Path Element
Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48496?
CVE-2025-48496 has not been assigned a specific severity rating, but it involves a potential vulnerability due to a controlled search path that can be exploited.
How do I fix CVE-2025-48496?
To mitigate CVE-2025-48496, it is recommended to upgrade to ValveLink version 14.0 or later.
Which Emerson ValveLink products are affected by CVE-2025-48496?
CVE-2025-48496 affects all versions of ValveLink SOLO, ValveLink DTM, ValveLink PRM, and ValveLink SNAP-ON prior to version 14.0.
What type of vulnerability is CVE-2025-48496?
CVE-2025-48496 is a path traversal vulnerability that allows unintended actors to control the search path for resources.
Is there a workaround for CVE-2025-48496?
There is no specific workaround for CVE-2025-48496; users are advised to upgrade their software to the latest version.