Improper Authentication Vulnerability in Eaton UPS Companion Software
CVE-2025-59887
8.6HIGH
What is CVE-2025-59887?
A security vulnerability exists in the Eaton UPS Companion software installer due to improper authentication of library files. This flaw could allow an attacker with access to the software package to execute arbitrary code, potentially compromising system integrity. Eaton has responded by addressing this issue in the latest version of the EUC software, now available for download.
Affected Version(s)
Eaton UPS Companion Software 0 < 3.0
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
