CVE-2025-46358

7.7

Emerson · ValveLink

Emerson ValveLink products lack sufficient protection mechanisms, potentially allowing for successful directed attacks against the software.

Executive summary

Emerson ValveLink products are susceptible to security bypass vulnerabilities, posing a significant risk of unauthorized system manipulation.

Vulnerability

The software fails to implement adequate protection mechanisms as defined by CWE-693, leaving it vulnerable to directed attacks. According to the CVSS vector, this vulnerability can be triggered by an unauthenticated local attacker without requiring user interaction.

Business impact

The identified vulnerability carries a CVSS score of 7.7, classifying it as a high-severity risk. Successful exploitation could lead to unauthorized control over critical industrial valve management software, potentially causing operational disruption, equipment damage, or loss of process integrity.

Remediation

Immediate Action: Update all instances of ValveLink (SOLO, DTM, PRM, and SNAP-ON) to version 14.0 or later immediately.

Proactive Monitoring: Monitor system access logs for unauthorized attempts to interact with ValveLink interfaces or unusual modifications to configuration files.

Compensating Controls: Restrict physical and logical access to systems running ValveLink software to authorized personnel only, and ensure that host-based security controls are active to limit unauthorized process execution.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high-severity nature of this vulnerability and its potential impact on industrial control environments, organizations must prioritize upgrading to ValveLink 14.0 or later. Failure to patch these systems leaves them susceptible to directed attacks that could compromise operational stability and safety.

More Emerson CVEs

Sources

Originally found and disclosed by Emerson reported these vulnerabilities to CISA., per the CVE Program record.