---
id: CVE-2025-59889
title: "Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the access to the software package.\_\n\nThis security issue has been fixed in the latest version of IPP…"
summary: "Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the access to the software package.\_\n\nThis security issue has been fixed in the latest version of IPP…"
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-427
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59889'
references:
  - url: >-
      https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2025-1009.pdf
    label: CybersecurityCOE@eaton.com
tags:
  - nvd
epss: 0.00177
epssPercentile: 0.06676
ingestedAt: '2026-10-08T11:31:27.366Z'
---

## Overview

Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the access to the software package. 

This security issue has been fixed in the latest version of IPP which is available on the Eaton download center.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
