CRITICAL🇵🇱 Wersja polska

CVE-2025-52549

CVSS 9.2v4.0pub. 2025-09-02upd. 2025-10-01

E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-522 (Insufficiently Protected Credentials) relies on the root password generation mechanism being based on parameters that are easily predictable or obtainable by an attacker. Each time the device starts, the firmware generates a new root password; however, the algorithm for its creation does not provide sufficient randomness or secrecy of input data. A remote attacker, without needing any privileges or victim interaction, can reproduce the password and log in as root to the Linux system on the device.

Impact

An attacker gains full administrative (root) privileges to the Linux operating system on the vulnerable device, enabling complete system takeover, configuration modification, data confidentiality breach, and potential disruption of industrial devices managed by the system.

Mitigation & patch

Update E3 Site Supervisor Control firmware to version 2.31F01 or later. Detailed information is available in the manufacturer's references and in the research report at https://www.armis.com/research/frostbyte10/

Who is affected

Copeland Site Supervisor devices: Cxe (860-1265), Cx (860-1260), Rx (860-1220), Bxe (860-1245), Bx (860-1240) with E3 Site Supervisor Control firmware versions below 2.31F01

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Copeland E3 Supervisory Controller Firmware

    OS
    Copeland
    < 2.31f01
  • Copeland Site Supervisor Bx 860 1240

    HW
    Copeland
    all versions
  • Copeland Site Supervisor Bxe 860 1245

    HW
    Copeland
    all versions
  • Copeland Site Supervisor Cx 860 1260

    HW
    Copeland
    all versions
  • Copeland Site Supervisor Cxe 860 1265

    HW
    Copeland
    all versions
  • Copeland Site Supervisor Rx 860 1220

    HW
    Copeland
    all versions
  • Copeland Site Supervisor Rxe 860 1225

    HW
    Copeland
    all versions
  • Copeland Site Supervisor Sf 860 1200

    HW
    Copeland
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-6519CRITICAL9.3PL ✓same product

Przewidywalne hasło domyślnego konta administratora w Copeland Site Supervisor

CVE-2025-52544HIGH8.8same product

E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenti...

CVE-2025-52545HIGH7.7same product

E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, w...

CVE-2025-52547HIGH8.7same product

E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. ...

CVE-2025-52550HIGH8.6same product

E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker ca...