Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).
References
Configurations
No configuration.
History
03 Nov 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
03 Nov 2025, 10:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004). |
03 Nov 2025, 08:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-03 08:15
Updated : 2025-11-04 15:41
NVD link : CVE-2025-48396
Mitre link : CVE-2025-48396
CVE.ORG link : CVE-2025-48396
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
