CVE-2025-52548
6.9
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: dd59f033-460c-4b88-a075-d4d3fedb6191 (Secondary)
Description
E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS.
Affected (1)
Products: Copeland: E3 Supervisory Controller Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.31f01 |
| Running on/with | Platform Versions |
|---|---|
Copeland Site Supervisor Bx 860 1240 | All versions |
Copeland Site Supervisor Bxe 860 1245 | All versions |
Copeland Site Supervisor Cx 860 1260 | All versions |
Copeland Site Supervisor Cxe 860 1265 | All versions |
Copeland Site Supervisor Rx 860 1220 | All versions |
Copeland Site Supervisor Rxe 860 1225 | All versions |
Copeland Site Supervisor Sf 860 1200 | All versions |
References (1)
Source: dd59f033-460c-4b88-a075-d4d3fedb6191
MitigationThird Party Advisory
Timeline
No history available yet.