Home

Description

The privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).

PUBLISHED Reserved 2025-05-20 | Published 2025-11-03 | Updated 2025-11-03 | Assigner Eaton




HIGH: 7.1CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-306 Missing Authentication for Critical Function

Product status

Default status
unaffected

Any version
affected

References

www.eaton.com/...ity/security-bulletins/etn-va-2025-1030.pdf

cve.org (CVE-2025-48397)

nvd.nist.gov (CVE-2025-48397)

Download JSON