E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters.
The vulnerability classified as CWE-522 (Insufficiently Protected Credentials) relies on the root password generation mechanism being based on parameters that are easily predictable or obtainable by an attacker. Each time the device starts, the firmware generates a new root password; however, the algorithm for its creation does not provide sufficient randomness or secrecy of input data. A remote attacker, without needing any privileges or victim interaction, can reproduce the password and log in as root to the Linux system on the device.
An attacker gains full administrative (root) privileges to the Linux operating system on the vulnerable device, enabling complete system takeover, configuration modification, data confidentiality breach, and potential disruption of industrial devices managed by the system.
Update E3 Site Supervisor Control firmware to version 2.31F01 or later. Detailed information is available in the manufacturer's references and in the research report at https://www.armis.com/research/frostbyte10/
Copeland Site Supervisor devices: Cxe (860-1265), Cx (860-1260), Rx (860-1220), Bxe (860-1245), Bx (860-1240) with E3 Site Supervisor Control firmware versions below 2.31F01
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCopeland E3 Supervisory Controller Firmware
OSCopeland< 2.31f01Copeland Site Supervisor Bx 860 1240
HWCopelandall versionsCopeland Site Supervisor Bxe 860 1245
HWCopelandall versionsCopeland Site Supervisor Cx 860 1260
HWCopelandall versionsCopeland Site Supervisor Cxe 860 1265
HWCopelandall versionsCopeland Site Supervisor Rx 860 1220
HWCopelandall versionsCopeland Site Supervisor Rxe 860 1225
HWCopelandall versionsCopeland Site Supervisor Sf 860 1200
HWCopelandall versions
Related vulnerabilities
Przewidywalne hasło domyślnego konta administratora w Copeland Site Supervisor
E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenti...
E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, w...
E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. ...
E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker ca...