CVE-2025-59889

8.6

Eaton · IPP software

Eaton IPP software contains an uncontrolled search path element vulnerability that allows an attacker with access to the software package to achieve arbitrary code execution.

Executive summary

A critical vulnerability in the Eaton IPP software installer allows local attackers to execute arbitrary code due to improper library file authentication.

Vulnerability

This is an uncontrolled search path element flaw (CWE-427) where the installer fails to properly authenticate library files, allowing for potential code injection by an attacker with local access.

Business impact

The ability for an attacker to execute arbitrary code on a system hosting Eaton IPP software poses a severe threat to operational integrity and data security. With a CVSS score of 8.6, this vulnerability represents a high risk, as successful exploitation could lead to full system compromise, unauthorized access to sensitive configurations, or the disruption of critical power management services.

Remediation

Immediate Action: Update the Eaton IPP software to the latest version available on the Eaton download center to ensure the inclusion of the security fix.

Proactive Monitoring: Monitor system logs for unusual installer activity or unauthorized file modifications in the installation directories.

Compensating Controls: Restrict local access to the software installation packages and ensure that only authorized users have the ability to execute installers on critical infrastructure management systems.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the severity of potential arbitrary code execution, administrators should prioritize the deployment of the updated Eaton IPP software. Organizations must ensure that all installations are performed from verified, official sources and that access to the software package itself is restricted to prevent unauthorized tampering with library files.

More Eaton CVEs

Sources

Originally found and disclosed by Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc., per the CVE Program record.