CRITICAL🇵🇱 Wersja polska

CVE-2025-6519

CVSS 9.3v4.0pub. 2025-09-02upd. 2025-10-10

E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user.

🤖 AI Analysis
How it works

The 'ONEDAY' user account is present by default in the device firmware and cannot be removed or modified by any administrator. The password for this account is generated dynamically each day, however the algorithm for its generation is predictable, allowing an attacker to calculate the current password without access to the device. The vulnerability is classified as CWE-522 (Insufficiently Protected Credentials), because the credential protection mechanism is insufficient.

Impact

An attacker with network access to the device can log in as an administrator and take full control of the device, modify configuration, and potentially affect managed industrial systems (e.g., cooling systems). The 'ONEDAY' account cannot be removed, making it impossible to permanently eliminate the threat without firmware updates.

Mitigation & patch

Update the firmware to version 2.31F01 or newer according to manufacturer references. Until the update is applied, it is recommended to isolate devices from public networks, restrict network access exclusively to trusted hosts, and monitor login attempts to the 'ONEDAY' account.

Who is affected

Copeland Site Supervisor CXE (860-1265), CX (860-1260), RX (860-1220), BXE (860-1245), and BX (860-1240) with firmware version below 2.31F01

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Copeland E3 Supervisory Controller Firmware

    OS
    Copeland
    < 2.31f01
  • Copeland Site Supervisor Bx 860 1240

    HW
    Copeland
    all versions
  • Copeland Site Supervisor Bxe 860 1245

    HW
    Copeland
    all versions
  • Copeland Site Supervisor Cx 860 1260

    HW
    Copeland
    all versions
  • Copeland Site Supervisor Cxe 860 1265

    HW
    Copeland
    all versions
  • Copeland Site Supervisor Rx 860 1220

    HW
    Copeland
    all versions
  • Copeland Site Supervisor Rxe 860 1225

    HW
    Copeland
    all versions
  • Copeland Site Supervisor Sf 860 1200

    HW
    Copeland
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-52549CRITICAL9.2PL ✓same product

Przewidywalne hasło root w urządzeniach Copeland Site Supervisor (E3)

CVE-2025-52544HIGH8.8same product

E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenti...

CVE-2025-52545HIGH7.7same product

E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, w...

CVE-2025-52547HIGH8.7same product

E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. ...

CVE-2025-52550HIGH8.6same product

E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker ca...