CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modifi...Show more |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 8.6 HIGH· v4 7.2 HIGH· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin access to the application services can ins...Show more |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 9.2 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters. |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 6.9 MEDIUM· v4 4.9 MEDIUM· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to t...Show more |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacker can use this command to continuously crash the application services. |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can i...Show more |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 7.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which returns all usernames and password hashes for the application services. |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 8.8 HIGH· v4 7.5 HIGH· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can a...Show more |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 5.3 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An attacker can authenticate by obtaining only the password hash. |