Database/Firmware, BMC & network fabric

Eaton UPS Companion (EUC) executable - library loading: Insecure library loading in the shipped executable gives
CVE-2025-67450Firmware, BMC & network fabricETN-VA-2025-1027curated
Impact
Insecure library loading in the shipped executable gives arbitrary code execution to an attacker with access to the software package. Persistent code on hosts that talk to the UPS, running with the privileges power-management agents typically hold.
Who can reach it
Local, requires access to the software package or its directory on the host.
What to do
Update to the fixed EUC version. Lock down the install directory permissions - power-management agents are installed to writable locations more often than they should be.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.