PT-2025-28650 · Emerson · Valvelink Products

Published

2025-07-08

·

Updated

2025-07-31

·

CVE-2025-52579

CVSS v2.0

9.7

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions: Emerson ValveLink Products (affected versions not specified)
Description: Emerson ValveLink Products store sensitive information in cleartext in memory. This sensitive memory may be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or if the programmer does not properly clear the memory before freeing it. This could lead to privilege escalation through parameter tampering.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Weakness Enumeration

Related Identifiers

BDU:2025-14624
CVE-2025-52579

Affected Products

Valvelink Products