The privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).
Metrics
Affected Vendors & Products
References
History
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eaton
Eaton brightlayer Software Suite |
|
| Vendors & Products |
Eaton
Eaton brightlayer Software Suite |
Mon, 03 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The privileged user could log in without sufficient credentials after enabling an application protocol. | The privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004). |
Mon, 03 Nov 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The privileged user could log in without sufficient credentials after enabling an application protocol. | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Eaton
Published: 2025-11-03T08:28:53.084Z
Updated: 2025-11-03T15:48:09.729Z
Reserved: 2025-05-20T04:07:25.101Z
Link: CVE-2025-48397
Updated: 2025-11-03T13:22:05.909Z
Status : Awaiting Analysis
Published: 2025-11-03T09:15:46.057
Modified: 2025-11-04T15:41:31.450
Link: CVE-2025-48397
No data.