Security Advisory

CVE-2025-48393

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-08-06 15:25:17
Last updated 2026-02-09 05:35:45
Assigner Eaton
CVSS score 5.7
State PUBLISHED

Description

The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton G4 PDU which is available on the Eaton download center.