{"id":"CVE-2025-11492","title":"In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS","summary":"In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic.…","severity":"critical","cvss":9.6,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-319"],"vendor":"connectwise","product":"automate","affected":["automate < 2025.9"],"patched":["automate 2025.9"],"published":"2025-10-16","updated":"2026-10-09","sourceUpdated":"2026-10-09T10:10:00.193","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-11492","references":[{"url":"https://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-2025.9-security-fix","label":"7d616e1a-3288-43b1-a0dd-0a65d3e70a49"}],"tags":["nvd","exploit-available"],"epss":0.00205,"epssPercentile":0.09619,"exploits":{"github":1,"githubRepos":["https://github.com/synap5e/connectwise-automate-AiTM-rce"],"checkedAt":"2026-10-09T12:54:06.036Z"},"exploitAvailable":true,"ingestedAt":"2026-10-09T12:53:29.092Z","slug":"CVE-2025-11492","body":"## Overview\n\nIn the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic. Additionally, the encryption method used to obfuscate some communications over the HTTP channel is updated in the Automate 2025.9 patch to enforce HTTPS for all agent communications.\n\n## Affected\n\n- `automate < 2025.9`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `automate 2025.9`","depth":"abyssal","depthScore":65,"depthScoreParts":{"impact":52.8,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}