Database/Firmware, BMC & network fabric

Eaton UPS Companion (EUC) executable - library loading: Insecure library loading in the shipped executable gives
CVSS 7.8CVE-2025-67450Firmware, BMC & network fabricETN-VA-2025-1027curated
Impact
Insecure library loading in the shipped executable gives arbitrary code execution to an attacker with access to the software package. Persistent code on hosts that talk to the UPS, running with the privileges power-management agents typically hold.
Who can reach it
Local, requires access to the software package or its directory on the host.
What to do
Update to the fixed EUC version. Lock down the install directory permissions - power-management agents are installed to writable locations more often than they should be.
References
Related entries
- Linux kernel (drivers/infiniband/sw/rxe): Two failed shared-receive-queue resizes in a row panic the node. The firstCVE-2025-68379 · Linux kernel (drivers/infiniband/sw/rxe)High
- Linux kernel mlxsw (Spectrum switch router, neighbour table): The driver stored neighbour pointers without holdingCVE-2025-68801 · Linux kernel mlxsw (Spectrum switch router, neighbour table)High
- Linux bnxt_re RoCE driver (bnxt_re_copy_err_stats out-of-bounds write): Out-of-bounds write in the Broadcom RoCECVE-2025-71092 · Linux bnxt_re RoCE driver (bnxt_re_copy_err_stats out-of-bounds write)High
- Linux kernel InfiniBand user MAD interface (ib_umad, /dev/infiniband/umad*): A process with access to the user MADCVE-2026-23243 · Linux kernel InfiniBand user MAD interface (ib_umad, /dev/infiniband/umad*)High
- Dell iDRAC Service Module (iSM) for Windows and Linux: Improper access control in the host-side iDRAC Service ModuleCVE-2026-23856 · Dell iDRAC Service Module (iSM) for Windows and LinuxHigh
- Linux kernel InfiniBand core dmabuf umem (GPUDirect RDMA path): When mapping a dmabuf-backed RDMA memory region failsCVE-2026-43128 · Linux kernel InfiniBand core dmabuf umem (GPUDirect RDMA path)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.