PT-2025-28650 · Emerson · Valvelink Products
Published
2025-07-08
·
Updated
2025-07-31
·
CVE-2025-52579
CVSS v2.0
9.7
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:P |
Name of the Vulnerable Software and Affected Versions:
Emerson ValveLink Products (affected versions not specified)
Description:
Emerson ValveLink Products store sensitive information in cleartext in memory. This sensitive memory may be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or if the programmer does not properly clear the memory before freeing it. This could lead to privilege escalation through parameter tampering.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Valvelink Products