Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or if the programmer does not properly clear the memory before freeing it.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00027}

epss

{'score': 0.00021}


Fri, 11 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00027}


Fri, 11 Jul 2025 00:00:00 +0000

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Thu, 10 Jul 2025 23:45:00 +0000

Type Values Removed Values Added
Description Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or if the programmer does not properly clear the memory before freeing it.
Title Emerson ValveLink Products Cleartext Storage of Sensitive Information in Memory
Weaknesses CWE-316
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2025-07-10T23:37:21.515Z

Updated: 2025-07-11T13:55:15.422Z

Reserved: 2025-06-30T14:34:56.212Z

Link: CVE-2025-52579

cve-icon Vulnrichment

Updated: 2025-07-11T13:55:12.422Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-11T00:15:26.597

Modified: 2025-07-15T13:14:49.980

Link: CVE-2025-52579

cve-icon Redhat

No data.