Eaton
Eaton Vulnerability Advisory on Network Cards
Pages
4
Time to read
5 mins
Publication
Language
English
Pages
4
Time to read
5 mins
Publication
Language
English
This document is a vulnerability advisory from Eaton, detailing a security issue related to improper server identity checks in network cards. The advisory identifies the vulnerability as CVE-2025-48393 and CVE-2026-22613, with a CVSS v3.1 base score of 5.7, indicating a medium risk level. It outlines the affected products, including Eaton Rack PDU G4 and Eaton Network M3, specifying that all versions prior to 3.5.0 and 2.3.3, respectively, are impacted. The document provides remediation steps, urging customers to update to the latest firmware versions to mitigate the identified risks. Additionally, it suggests mitigation measures for users unable to apply patches, such as restricting network access and ensuring secure configurations. The advisory also emphasizes the importance of following general security best practices to enhance device protection and reduce exposure to vulnerabilities. Lastly, it acknowledges the contribution of a researcher in identifying the vulnerabilities and provides contact information for further support.