Executive Summary
In October 2025, ConnectWise disclosed and patched critical vulnerabilities in its Automate remote monitoring and management platform, widely used by managed service providers (MSPs) and enterprises. The most severe issue (CVE-2025-11492, CVSS 9.6) allowed agents to communicate sensitive information in cleartext over unencrypted HTTP, exposing them to adversary-in-the-middle (AiTM) attacks capable of intercepting or altering management traffic, including credentials and update payloads. A second flaw (CVE-2025-11493, CVSS 8.8) enabled attackers to bypass update integrity checks, facilitating the delivery of malicious software disguised as legitimate updates. Together, these vulnerabilities posed a significant supply chain threat, enabling network-based attackers to compromise customer environments via trusted management channels.
This incident underscores the heightened attention on software supply chain vulnerabilities and AiTM risks, particularly among platforms entrusted with privileged access across thousands of customer endpoints. With adversaries increasingly exploiting weak encryption, incomplete update verification, and RMM tool supply chains, organizations must urgently strengthen controls around update validation, encrypted communications, and least privilege management to stay ahead of evolving attacker tactics.
Why This Matters Now
Supply chain attacks leveraging RMM tools are on the rise, targeting platforms with deep access into enterprise networks. The ConnectWise Automate vulnerabilities illustrate urgent risks from unencrypted traffic and weak update integrity, which attackers can leverage to compromise entire customer environments. Organizations must act swiftly to patch, enforce encryption, and adopt modern zero trust practices.
Attack Path Analysis
Attackers exploited insecure HTTP configurations in ConnectWise Automate agents (CVE-2025-11492) to gain initial access via adversary-in-the-middle (AiTM) attacks, intercepting or modifying cleartext communications. They escalated privileges by delivering malicious update payloads, exploiting the lack of integrity verification (CVE-2025-11493). The compromised agents enabled lateral movement through the RMM platform to additional client machines. Attackers established command and control via the altered and unauthorized update channels. Sensitive data or credentials could then be exfiltrated through these compromised connections, finally enabling potential malware distribution or operational disruption impacting managed endpoints.
Kill Chain Progression
Initial Compromise
Description
A network-based attacker intercepted unencrypted HTTP communications between Automate agents and servers, leveraging the AiTM flaw (CVE-2025-11492) to impersonate a legitimate update source.
Related CVEs
CVE-2025-11492
CVSS 9.6In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS, allowing an on-path attacker to intercept, modify, or replay agent-server traffic.
Affected Products:
ConnectWise Automate – < 2025.9
Exploit Status:
no public exploitCVE-2025-11493
CVSS 8.8The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, allowing an on-path attacker to substitute malicious files for legitimate ones.
Affected Products:
ConnectWise Automate – < 2025.9
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Adversary-in-the-Middle
Network Sniffing
Web Protocols
Supply Chain Compromise: Compromise Software Dependencies and Development Tools
Compromise Client Software Binary
Valid Accounts
Ingress Tool Transfer
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Use Strong Cryptography and Security Protocols
Control ID: 4.2.1
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA (Digital Operational Resilience Act) – ICT Risk Management - Preventive Measures
Control ID: Article 9.2
CISA Zero Trust Maturity Model 2.0 – Secure Software Supply Chain
Control ID: Pillar: Devices & Applications
NIS2 Directive – Supply Chain Security
Control ID: Annex I, Section 2(d), Technical Measures
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
MSPs using ConnectWise Automate face critical supply chain attack risks through AiTM vulnerabilities enabling malicious update injection and credential interception across client networks.
Computer Software/Engineering
Software companies relying on RMM platforms vulnerable to cleartext transmission flaws allowing adversaries to substitute legitimate updates with malware through compromised communication channels.
Financial Services
Financial institutions using managed IT services exposed to compliance violations and data breaches through unencrypted RMM communications compromising HIPAA and PCI requirements.
Health Care / Life Sciences
Healthcare organizations face HIPAA compliance violations and patient data exposure through compromised MSP connections enabling unauthorized access to sensitive medical information systems.
Sources
- ConnectWise fixes Automate bug allowing AiTM update attackshttps://www.bleepingcomputer.com/news/security/connectwise-fixes-automate-bug-allowing-aitm-update-attacks/Verified
- ConnectWise Automate 2025.9 Security Fixhttps://www.connectwise.com/company/trust/security-bulletins/connectwise-automate-2025.9-security-fixVerified
- CVE-2025-11492 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-11492Verified
- CVE-2025-11493 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-11493Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust network segmentation, east-west traffic controls, and encrypted communication enforcement would have disrupted adversary-in-the-middle exploitation, limited lateral attacker movement, and detected anomalous update activity—significantly reducing impact throughout the kill chain.
Control: Encrypted Traffic (HPE)
Mitigation: Prevented interception and modification of agent communications.
Control: Zero Trust Segmentation
Mitigation: Constrained privilege escalation paths to critical RMM components.
Control: East-West Traffic Security
Mitigation: Detected and blocked unauthorized lateral agent-to-agent or agent-to-server flows.
Control: Threat Detection & Anomaly Response
Mitigation: Detected suspicious remote command or update activity to alert security teams.
Control: Egress Security & Policy Enforcement
Mitigation: Blocked unauthorized outbound data transfers or suspicious exfiltration attempts.
Limited blast radius and reduced attack efficacy against managed endpoints.
Impact at a Glance
Affected Business Functions
- Remote Monitoring and Management
- Software Update Deployment
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive agent-server communications, including credentials and update payloads, due to interception and modification by an on-path attacker.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce encryption (MACsec/IPsec) for all RMM agent communications and update channels to eliminate adversary-in-the-middle attack opportunities.
- • Implement Zero Trust segmentation and microsegmentation to isolate update infrastructure and limit lateral attacker movement within cloud and hybrid environments.
- • Apply east-west workload traffic controls, with continuous monitoring to detect unauthorized pivots and rapid anomaly response.
- • Establish strong egress filtering and policy enforcement to prevent data exfiltration and external communication from compromised systems.
- • Regularly audit and update RMM/RMM-like service configurations for secure defaults, ensuring integrity checks and runtime enforcement are in place for all software updates.



