E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin access to the application services can install a malicious firmware upgrade.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCopeland E3 Supervisory Controller Firmware
OSCopeland< 2.31f01Copeland Site Supervisor Bx 860 1240
HWCopelandall versionsCopeland Site Supervisor Bxe 860 1245
HWCopelandall versionsCopeland Site Supervisor Cx 860 1260
HWCopelandall versionsCopeland Site Supervisor Cxe 860 1265
HWCopelandall versionsCopeland Site Supervisor Rx 860 1220
HWCopelandall versionsCopeland Site Supervisor Rxe 860 1225
HWCopelandall versionsCopeland Site Supervisor Sf 860 1200
HWCopelandall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2025-6519CRITICAL9.3PL ✓same product
Przewidywalne hasło domyślnego konta administratora w Copeland Site Supervisor
CVE-2025-52549CRITICAL9.2PL ✓same product
Przewidywalne hasło root w urządzeniach Copeland Site Supervisor (E3)
CVE-2025-52545HIGH7.7same product
E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, w...
CVE-2025-52547HIGH8.7same product
E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. ...
CVE-2025-52544HIGH8.8same product
E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenti...