ConnectWise released a security update to address vulnerabilities, one of them with critical severity, in Automate product that could expose sensitive communications to interception and modification. ConnectWise Automate is a remote monitoring and management (RMM) platform used by managed service providers (MSPs), IT service companies, and internal IT departments in large enterprises. In typical deployments, it acts as a central management hub with high priviliges to control thousands of client machines. The most severe flaw the vendor fixed is tracked as CVE-2025-11492. With a severity rating of 9.6, the vulnerability allows cleartext transmission of sensitive information. Specifically, agents could be configured to communicate over the insecure HTTP instead of the encrypted HTTPS, which could be exploited in adversary-in-the-middle (AitM) attacks to intercept or modify the traffic, including commands, credentials, and update payloads. “In on-prem environments, agents could be configured to use HTTP or rely on encryption, that could allow a network-based adversary to view or modify traffic or substitute malicious updates,” ConnectWise explains. The second vulnerability is identified as CVE-2025-11493 (8.8 severity score) and consists in a lack of integrity verification (checksum or digital signature) for update packages along with their dependencies and integrations. By combining the two security issues, an attacker could push malicious files (e.g. malware, updates) as legi...
ConnectWise fixes Automate bug allowing AiTM update attacks
BleepingComputer
·Bill Toulas
·Published Oct 17, 2025
·Updated
Affected Software
1 affected component
ConnectWise Automate
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security update released by ConnectWise to fix vulnerabilities in their Automate product.
2
What vulnerabilities are addressed in the ConnectWise Automate update?
The update addresses critical vulnerabilities that could expose sensitive communications to interception and modification.
3
What security risks are associated with the Automate product?
The security risks include the potential for AiTM (Adversary-in-the-Middle) update attacks that can compromise data integrity.
4
Who is affected by the vulnerabilities in ConnectWise Automate?
Users of the ConnectWise Automate software are affected by the vulnerabilities that allow for possible sensitive data exposure.
5
What should ConnectWise Automate users do in response to this article?
ConnectWise Automate users should apply the latest security update to mitigate the risks associated with the identified vulnerabilities.