Eaton BLSS Arbitrary Code Execution Vulnerability via Improper File Upload Validation

Vulnerability

A vulnerability allowing arbitrary code execution exists in Eaton BLSS versions prior to 7.3.0.SCP004, due to inadequate validation of the file upload feature.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the server where Eaton BLSS is running.

Remediation

Users can upgrade to Eaton BLSS version 7.3.0.SCP004 or later to address this vulnerability.

Added: Nov 3, 2025, 8:16 AM
Updated: Nov 3, 2025, 10:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.0
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.