Executive brief
Emerson ValveLink products, which are used to configure and monitor digital valve controllers in industrial environments, contain a vulnerability in how they process input data. An attacker with local access to the system could exploit this flaw to tamper with device parameters or system data. This could lead to unauthorized changes in valve operations, potentially impacting industrial processes and safety controls.
Technical details
An improper input validation vulnerability (CWE-20) exists in Emerson ValveLink products (SOLO, DTM, PRM, and SNAP-ON) in versions prior to 14.0. The software fails to correctly validate that input data possesses the required properties for safe processing. An attacker with local access to the host system can exploit this vulnerability to modify or tamper with sensitive parameters. While the attack complexity is high, successful exploitation results in a high impact on data integrity. Users are advised to upgrade to ValveLink version 14.0 or later to mitigate this risk.
Affected products
- Emerson ValveLink SOLO All versions prior to 14.0
- Emerson ValveLink DTM All versions prior to 14.0
- Emerson ValveLink PRM All versions prior to 14.0
- Emerson ValveLink SNAP-ON All versions prior to 14.0
Timeline
- 2025-07-08: advisory: Initial publication of ICSA-25-189-01 by CISA
- 2025-07-10: disclosed: NVD publication date