CVE-2025-48397
7.1Eaton · Brightlayer Software Suite (BLSS)
Eaton Brightlayer Software Suite contains a missing authentication vulnerability that allows privileged users to bypass credential requirements after enabling specific application protocols.
Executive summary
A critical authentication bypass flaw in Eaton Brightlayer Software Suite allows privileged users to access sensitive functions without proper credentials, posing a significant risk to system integrity.
Vulnerability
The vulnerability is categorized as CWE-306, representing missing authentication for a critical function. An attacker with low-level privileges can exploit this flaw to perform unauthorized actions after an application protocol is enabled.
Business impact
The ability for a privileged user to bypass authentication mechanisms can lead to full system compromise, including unauthorized data access, modification, or disruption of critical monitoring services. With a CVSS score of 7.1, this high-severity flaw threatens the confidentiality, integrity, and availability of the affected software suite, potentially resulting in operational downtime or severe security breaches within industrial control environments.
Remediation
Immediate Action: Update the Eaton Brightlayer Software Suite to version 7.3.0.SCP004 or later to apply the necessary security patch.
Proactive Monitoring: Review system access logs for unusual login patterns or anomalous activity occurring immediately after the activation of application protocols.
Compensating Controls: Restrict network access to the management interface of the Brightlayer Software Suite to trusted IP addresses only, and implement strict internal network segmentation to limit the reach of unauthorized users.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for total system impact, organizations utilizing Eaton Brightlayer Software Suite must prioritize the application of the provided patch. Administrators should verify their current version and upgrade to 7.3.0.SCP004 immediately to eliminate the risk of authentication bypass. Failure to patch leaves administrative functions exposed to internal threat actors who could leverage this bypass to escalate their control over the environment.