{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-53471",
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "state": "PUBLISHED",
        "assignerShortName": "icscert",
        "dateReserved": "2025-06-30T14:34:56.244Z",
        "datePublished": "2025-07-10T23:45:39.592Z",
        "dateUpdated": "2026-06-04T20:45:43.072Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
                "shortName": "icscert",
                "dateUpdated": "2026-06-04T20:45:43.072Z"
            },
            "title": "Emerson ValveLink Products Improper Input Validation",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-20",
                            "description": "CWE-20",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Emerson",
                    "product": "ValveLink SOLO",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "ValveLink 14.0",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "ValveLink 14.0"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Emerson",
                    "product": "ValveLink DTM",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "ValveLink 14.0",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "ValveLink 14.0"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Emerson",
                    "product": "ValveLink PRM",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "ValveLink 14.0",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "ValveLink 14.0"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Emerson",
                    "product": "ValveLink SNAP-ON",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "ValveLink 14.0",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "ValveLink 14.0"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Emerson ValveLink products \nreceive input or data, but does not validate or incorrectly \nvalidates that the input has the properties that are required to process\n the data safely and correctly.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Emerson ValveLink products \nreceive input or data, but does not validate or incorrectly \nvalidates that the input has the properties that are required to process\n the data safely and correctly."
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-189-01"
                },
                {
                    "url": "https://www.emerson.com/en-us/support/security-notifications"
                },
                {
                    "url": "https://www.emerson.com/en-us/support/software-downloads-drivers"
                },
                {
                    "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-189-01.json"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "LOCAL",
                        "attackComplexity": "HIGH",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "NONE",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "NONE",
                        "baseSeverity": "MEDIUM",
                        "baseScore": 5.1,
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
                    }
                },
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "LOCAL",
                        "attackComplexity": "HIGH",
                        "attackRequirements": "NONE",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "NONE",
                        "subConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "HIGH",
                        "subIntegrityImpact": "NONE",
                        "vulnAvailabilityImpact": "NONE",
                        "subAvailabilityImpact": "NONE",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "MEDIUM",
                        "baseScore": 5.9,
                        "vectorString": "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "Emerson recommends users update their Valvelink software to ValveLink \n14.0 or later. The upgrade can be downloaded from the Emerson  website https://www.emerson.com/en-us/support/software-downloads-drivers  .For more information see the associated  Emerson security notification. https://www.emerson.com/en-us/support/security-notifications",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Emerson recommends users update their Valvelink software to ValveLink \n14.0 or later. The upgrade can be downloaded from the Emerson <a target=\"_blank\" rel=\"nofollow\" href=\"https://www.emerson.com/en-us/support/software-downloads-drivers\">website</a>&nbsp;.<p>For more information see the associated <a target=\"_blank\" rel=\"nofollow\" href=\"https://www.emerson.com/en-us/support/security-notifications\">Emerson security notification.</a></p>\n\n<br>"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Emerson reported these vulnerabilities to CISA.",
                    "type": "finder"
                }
            ],
            "source": {
                "advisory": "ICSA-25-189-01",
                "discovery": "INTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-07-11T13:29:05.416717Z",
                                "id": "CVE-2025-53471",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-07-11T13:29:12.368Z"
                }
            }
        ]
    }
}