The privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-11-03 09:15
Updated : 2025-11-04 15:41
NVD link : CVE-2025-48397
Mitre link : CVE-2025-48397
CVE.ORG link : CVE-2025-48397
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
