CVE-2025-48393

CVE Details

Basic Information

Title CVE-2025-48393
Type cve
Published 2025-08-06T15:25:17.947Z
Modified 2025-08-06T15:52:52.971Z

Product Information

Vendor Eaton
Product G4 PDU
Version 0

CVSS Information

Base Score 5.7 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L

AI Analysis

AI Description A vulnerability in Eaton’s G4 PDU allows potential Man-in-the-middle attacks due to insecure server identity checks during firmware upgrades. This has been fixed in the latest update.
AI Severity Medium
AI Vendor Eaton
AI Product G4 PDU
AI Version 0

Affected Products

  • Eaton G4 PDU 0

Additional Information

CWE List CWE-295
Source Eaton

Description

The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest version which is available on the Eaton download center.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.