Eaton
Eaton Vulnerability Advisory for Brightlayer Software Suite
Pages
4
Time to read
4 mins
Publication
Language
English
Pages
4
Time to read
4 mins
Publication
Language
English
This document is a vulnerability advisory released by Eaton regarding the Brightlayer Software Suite (BLSS). It outlines a high-severity vulnerability identified as CVE-2025-48397, which affects all versions of BLSS up to v7.3.x. The advisory emphasizes the importance of implementing security patch 7.3.0.SCP004 to remediate the issue, as it allows privileged users to log in without sufficient credentials after enabling Active Directory (LDAP) functionality. Additionally, the document provides mitigation measures for users unable to apply the patch, including restricting access to the host system, ensuring control systems are behind securely configured firewalls, and sourcing BLSS from official distributors. General security best practices are also detailed, such as limiting exposure to external networks, deploying firewalls, and regularly updating software. The advisory concludes with contact information for further support and a legal disclaimer regarding the information provided.