Eaton Vulnerabilities Allow Attackers to Execute Arbitrary Code on Host Systems
## Cybersecurity Advisory: Eaton UPS Companion Software Vulnerabilities
Cybersecurity Advisory: Eaton UPS Companion Software Vulnerabilities
Eaton has released a critical security advisory regarding multiple high-severity vulnerabilities in its UPS Companion software. These vulnerabilities could potentially allow attackers to execute arbitrary code on affected systems.
The advisory, identified as ETN-VA-2025-1026, highlights two vulnerabilities with CVSS scores ranging from high to medium severity.
CVE ID CVSS v3.1 Score Severity Vulnerability Type
CVE-2025-59887 8.6 High Insecure Library Loading
CVE-2025-59888 6.7 Medium Improper Quotation
Eaton has released a critical security advisory regarding multiple high-severity vulnerabilities in its UPS Companion software.
The first vulnerability, CVE-2025-59887, with a CVSS score of 8.6, involves insecure library loading in the Eaton IPP software installer. This flaw can enable an attacker with access to the software package to execute arbitrary code, potentially compromising confidentiality, integrity, and availability.
The second vulnerability, CVE-2025-59888, scores 6.7 on the CVSS scale and affects the Eaton UPS Companion software due to improper quoting in search paths. Attackers with file system access could exploit this to execute arbitrary code, although high-level privileges are required.
All versions of Eaton UPS Companion software prior to version 3.0 are affected. Eaton strongly recommends upgrading to version 3.0, which includes patches for both vulnerabilities. It is advised to download software only from Eaton's official distribution channels to prevent supply chain attacks.
For those unable to apply patches immediately, Eaton suggests several mitigation measures:
Restricting access to host systems to authorized personnel only Implementing secure firewalls for control system networks Ensuring software is sourced from official channels Deploying control systems behind barrier devices and isolating them from business networks
Eaton's cybersecurity team recommends adopting security best practices, including changing default passwords, enabling audit logs, disabling unused services, and conducting regular security assessments. Organizations needing further support can contact Eaton’s cybersecurity services team or visit the company's dedicated cybersecurity website for guidance.
Based on reporting by GBHackers.
