CVE-2025-52579: Emerson ValveLink Products Cleartext Storage of Sensitive Information in Memory
Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or if the programmer does not properly clear the memory before freeing it.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52579?
CVE-2025-52579 has been rated as a high-severity vulnerability due to the potential exposure of sensitive information stored in cleartext.
How do I fix CVE-2025-52579?
To mitigate CVE-2025-52579, upgrade to Emerson ValveLink version 14.0 or later, which addresses the vulnerability.
What products are affected by CVE-2025-52579?
CVE-2025-52579 affects all versions of Emerson ValveLink SOLO, DTM, PRM, and SNAP-ON prior to version 14.0.
What type of sensitive information is compromised in CVE-2025-52579?
CVE-2025-52579 allows sensitive information to be stored in cleartext in memory, potentially exposing it during system crashes or improper memory handling.
Can CVE-2025-52579 lead to data leaks?
Yes, CVE-2025-52579 can lead to data leaks if sensitive information in memory is saved to disk or accessed through core dumps.