Eaton Vulnerabilities Allow Attackers to Execute Arbitrary Code on Host Systems
ID: 00fe9640-5432-5853-9973-7a96057e935c
STIX ID: report--00fe9640-5432-5853-9973-7a96057e935c
Feed Name: GBHackers
Threat Score
Eaton issued advisory ETN-VA-2025-1026 describing two vulnerabilities in its UPS Companion/IPP installer (CVE-2025-59887, CVSS 8.6 - insecure library loading; CVE-2025-59888, CVSS 6.7 - improper quoting) that could enable local arbitrary code execution; Eaton recommends upgrading to version 3.0, obtaining software from official channels, and applying mitigations for organizations that cannot patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
