Copeland
Copeland E3 Supervisory Controller Firmware: vulnerabilidades y CVE
Copeland E3 Supervisory Controller Firmware tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-6519 | Crítica (9.3) | 0.52% | — | 2 sept 2025 | E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or… |
| CVE-2025-52550 | Alta (8.6) | 0.22% | — | 2 sept 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin access to the application services can… |
| CVE-2025-52549 | Crítica (9.2) | 0.47% | — | 2 sept 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters. |
| CVE-2025-52547 | Alta (8.7) | 0.34% | — | 2 sept 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacker can use this command to continuously crash the application services. |
| CVE-2025-52546 | Media (5.1) | 0.20% | — | 2 sept 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can… |
| CVE-2025-52545 | Alta (7.7) | 0.26% | — | 2 sept 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which returns all usernames and password hashes for the application services. |
| CVE-2025-52544 | Alta (8.8) | 0.36% | — | 2 sept 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can… |
| CVE-2025-52543 | Media (5.3) | 0.31% | — | 2 sept 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An attacker can authenticate by obtaining only the password hash. |
| CVE-2025-52548 | Media (6.9) | 0.34% | — | 2 sept 2025 | E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.