Eaton UPS Companion Software Improper Authentication Vulnerability Leading to Arbitrary Code Execution

Vulnerability

A vulnerability in the Eaton UPS Companion software installer has been identified, stemming from improper authentication of library files. This flaw could allow an attacker with access to the software package to execute arbitrary code. The issue has been addressed in the latest version of the Eaton UPS Companion software, available for download from the Eaton download center.

Impact

Exploitation of this vulnerability could result in arbitrary code execution on the affected system.

Remediation

Users are advised to update to the latest version of the Eaton UPS Companion software, available on the Eaton download center.

Added: Dec 26, 2025, 7:31 AM
Updated: Dec 26, 2025, 7:31 AM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
10.0
exploitability
3.3
remediation
7.7
relevance
1.7
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.