Cyber Posture

CVE-2025-22495

High

Published: 24 February 2025

Published
24 February 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 8.4 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
EPSS Score 0.0008 24.1th percentile
Risk Priority 17 60% EPSS · 20% KEV · 20% CVSS

Description

An improper input validation vulnerability was discovered in the NTP server configuration field of the Network-M2 card. This could result in an authenticated high privileged user having the ability to execute arbitrary commands. The vulnerability has been resolved in the version 3.0.4. Note - Network-M2 has been declared end-of-life in early 2024 and Network-M3 has been released as a fit-and-functional replacement.

Security Summary

CVE-2025-22495 is an improper input validation vulnerability (CWE-78) in the NTP server configuration field of the Eaton Network-M2 card, a network interface used for power management in UPS and related systems. This flaw allows an authenticated high-privileged user to execute arbitrary commands on the device. The vulnerability has been addressed in Network-M2 firmware version 3.0.4 and carries a CVSS v3.1 base score of 8.4 (AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H).

Exploitation requires an attacker to have high privileges (PR:H) on the affected Network-M2 card, network access (AV:N), and the ability to trigger user interaction (UI:R), such as confirming a malicious input. Successful exploitation enables arbitrary command execution with high confidentiality, integrity, and availability impacts (C:I:A:H), and changes the scope (S:C) to potentially affect broader system components.

Eaton's security bulletin (etn-va-2025-1004.pdf) details the patch in firmware version 3.0.4 as the primary mitigation. Additionally, the Network-M2 card reached end-of-life in early 2024, with Network-M3 released as a direct functional replacement; organizations are advised to upgrade to supported hardware to avoid unpatched exposure.

No public reports of real-world exploitation are available as of the CVE publication on 2025-02-24.

Details

CWE(s)
CWE-78

References