PT-2025-44757 · Eaton · Eaton Blss

CVE-2025-48396

·

Publicado

2025-11-03

·

Atualizado

2025-11-08

CVSS v3.1

8.3

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eaton BLSS versions prior to 7.3.0.SCP004
Description Improper validation of the file upload functionality in Eaton BLSS can lead to arbitrary code execution.
Recommendations Update to Eaton BLSS version 7.3.0.SCP004 or later.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-48396

Produtos afetados

Eaton Blss