CVE-2025-50109: Emerson ValveLink Products Cleartext Storage of Sensitive Information in Memory
Published Jul 10, 2025
·Updated
Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to another control sphere.
Affected Software
4 affected components
Emerson ValveLink SOLO: All versions prior to ValveLink 14.0
Emerson ValveLink DTM: All versions prior to ValveLink 14.0
Emerson ValveLink PRM: All versions prior to ValveLink 14.0
Emerson ValveLink SNAP-ON: All versions prior to ValveLink 14.0
Remediation
Information
Emerson recommends users update their Valvelink software to ValveLink
14.0 or later. The upgrade can be downloaded from the Emerson website https://www.emerson.com/en-us/support/software-downloads-drivers .For more information see the associated Emerson security notification. https://www.emerson.com/en-us/support/security-notifications
Event History
Jul 10, 2025
CVE Published
via MITRE·11:39 PM
Data Sourced
via MITRE·11:39 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via ICS·11:41 PM
SeverityWeaknessAffected Software
Jul 11, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-50109?
CVE-2025-50109 is classified as a high severity vulnerability due to the exposure of sensitive information.
2
How do I fix CVE-2025-50109?
To fix CVE-2025-50109, upgrade to ValveLink version 14.0 or later.
3
What products are affected by CVE-2025-50109?
CVE-2025-50109 affects all versions of Emerson ValveLink SOLO, DTM, PRM, and SNAP-ON prior to version 14.0.
4
What type of information is stored in cleartext in CVE-2025-50109?
CVE-2025-50109 allows sensitive information to be stored in cleartext, which may include configuration details and credentials.
5
Is there a known exploit for CVE-2025-50109?
As of now, no specific exploit for CVE-2025-50109 has been publicly reported, but the vulnerability poses a significant risk due to the sensitive data exposure.