E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user.
The 'ONEDAY' user account is present by default in the device firmware and cannot be removed or modified by any administrator. The password for this account is generated dynamically each day, however the algorithm for its generation is predictable, allowing an attacker to calculate the current password without access to the device. The vulnerability is classified as CWE-522 (Insufficiently Protected Credentials), because the credential protection mechanism is insufficient.
An attacker with network access to the device can log in as an administrator and take full control of the device, modify configuration, and potentially affect managed industrial systems (e.g., cooling systems). The 'ONEDAY' account cannot be removed, making it impossible to permanently eliminate the threat without firmware updates.
Update the firmware to version 2.31F01 or newer according to manufacturer references. Until the update is applied, it is recommended to isolate devices from public networks, restrict network access exclusively to trusted hosts, and monitor login attempts to the 'ONEDAY' account.
Copeland Site Supervisor CXE (860-1265), CX (860-1260), RX (860-1220), BXE (860-1245), and BX (860-1240) with firmware version below 2.31F01
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCopeland E3 Supervisory Controller Firmware
OSCopeland< 2.31f01Copeland Site Supervisor Bx 860 1240
HWCopelandall versionsCopeland Site Supervisor Bxe 860 1245
HWCopelandall versionsCopeland Site Supervisor Cx 860 1260
HWCopelandall versionsCopeland Site Supervisor Cxe 860 1265
HWCopelandall versionsCopeland Site Supervisor Rx 860 1220
HWCopelandall versionsCopeland Site Supervisor Rxe 860 1225
HWCopelandall versionsCopeland Site Supervisor Sf 860 1200
HWCopelandall versions
Related vulnerabilities
Przewidywalne hasło root w urządzeniach Copeland Site Supervisor (E3)
E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenti...
E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, w...
E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. ...
E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker ca...