Copeland
copeland
32 CVEs • 14 products
Products (14)
Click to collapseToggle
Products (14)
Click to collapse
CVEs (32)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareJun 17, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareJun 17, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filenam...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareJun 17, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to...Show more |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modifi...Show more |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 8.6 HIGH· v4 7.2 HIGH· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin access to the application services can ins...Show more |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 9.2 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters. |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 6.9 MEDIUM· v4 4.9 MEDIUM· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to t...Show more |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacker can use this command to continuously crash the application services. |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can i...Show more |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 7.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which returns all usernames and password hashes for the application services. |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 8.8 HIGH· v4 7.5 HIGH· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can a...Show more |
1Copeland 1E3 Supervisory Controller Firmware Jun 17, 2026 Sep 2, 2025 5.3 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An attacker can authenticate by obtaining only the password hash. |