use a fixed or controlled search path to find resources, but one or
more locations in that path can be under the control of unintended
actors.
No analysis available yet.
Vendor Solution
Emerson recommends users update their Valvelink software to ValveLink 14.0 or later. The upgrade can be downloaded from the Emerson website https://www.emerson.com/en-us/support/software-downloads-drivers .For more information see the associated Emerson security notification. https://www.emerson.com/en-us/support/security-notifications
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21093 | Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors. |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Fri, 11 Jul 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors. | |
| Title | Emerson ValveLink Products Uncontrolled Search Path Element | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-07-11T13:54:00.868Z
Reserved: 2025-06-30T14:34:56.236Z
Link: CVE-2025-48496
Updated: 2025-07-11T13:53:56.918Z
Status : Awaiting Analysis
Published: 2025-07-11T00:15:25.743
Modified: 2025-07-15T13:14:49.980
Link: CVE-2025-48496
No data.
OpenCVE Enrichment
Updated: 2025-07-12T23:05:36Z
EUVD