Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).
Metrics
Affected Vendors & Products
References
History
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eaton
Eaton brightlayer Software Suite |
|
| Vendors & Products |
Eaton
Eaton brightlayer Software Suite |
Mon, 03 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. | Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004). |
Mon, 03 Nov 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Eaton
Published: 2025-11-03T07:57:22.765Z
Updated: 2025-11-04T10:44:25.658Z
Reserved: 2025-05-20T04:07:25.101Z
Link: CVE-2025-48396
Updated: 2025-11-03T13:10:24.997Z
Status : Awaiting Analysis
Published: 2025-11-03T08:15:34.077
Modified: 2025-11-04T15:41:31.450
Link: CVE-2025-48396
No data.