Back to Database
Status published
High
CVE-2025-48397
The privileged user could log in without sufficient credentials after...
Vulnerability Description
The privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-48397
Credits & Attribution
No credits recorded in the NVD database.
More from Eaton
View All →CVE-2025-67450
Due to insecure library loading in the Eaton UPS Companion...
High
7.8
CVE-2025-59890
Improper input sanitization in the file archives upload functionality of...
High
7.3
CVE-2025-59889
Improper authentication of library files in the Eaton IPP software...
High
8.6
CVE-2025-59888
Improper quotation in search paths in the Eaton UPS Companion...
Medium
6.7
CVE-2025-59887
Improper authentication of library files in the Eaton UPS Companion...
High
8.6
Affected Vendor
Eaton
View all reports →Affected Software
Eaton Brightlayer Software Suite (BLSS)
Vulnerable Versions:
0
Timeline
Official Publish:
November 3rd, 2025
Last Modified:
November 3rd, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H