Database/Firmware, BMC & network fabric

Eaton UPS Companion (EUC) software installer: The installer does not properly authenticate the library files it loads
Impact
The installer does not properly authenticate the library files it loads, so an attacker who can place a file alongside the installation package gets arbitrary code execution during install - at whatever privilege the installer runs with, which is administrative. The exposure window is your own deployment process.
Who can reach it
An attacker with write access to wherever the installation package is staged - a shared drive, a downloads folder, an imaging share.
What to do
Use the fixed EUC version from Eaton's download centre and stage installers somewhere with restricted write access. Verify package hashes before running. Companion issues CVE-2025-59888 (unquoted search path) and CVE-2025-67450 (insecure library loading) have the same fix and the same mitigation.
References
Related entries
- Eaton Tripp Lite series PADM firmware (rack PDU / ATS management): Unauthenticated authentication bypass givesCVE-2026-22620 · Eaton Tripp Lite series PADM firmware (rack PDU / ATS management)High
- Arista EOS: crafted gNSI Credentialz request can grant an account privileges beyond what was configuredCVE-2026-73454 · Arista EOS gNSI Credentialz serviceHigh
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsNCVD-2021-003-infiniband-rocev2-transport-rnic · InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsNCVD-2021-009-infiniband-rocev2-transport-rnic · InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh
- NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmet: NeVerMore implemented seven attacksNCVD-2022-002-nvme-over-fabrics-protocol-over · NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmetHigh
- Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6: Improper access controlCVE-2026-20898 · Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.