E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS.
References
Link | Resource |
---|---|
https://www.armis.com/research/frostbyte10/ | Mitigation Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
01 Oct 2025, 18:25
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.9 |
First Time |
Copeland site Supervisor Bxe 860-1245
Copeland site Supervisor Sf 860-1200 Copeland Copeland site Supervisor Cxe 860-1265 Copeland site Supervisor Rx 860-1220 Copeland site Supervisor Cx 860-1260 Copeland site Supervisor Bx 860-1240 Copeland e3 Supervisory Controller Firmware Copeland site Supervisor Rxe 860-1225 |
|
References | () https://www.armis.com/research/frostbyte10/ - Mitigation, Third Party Advisory | |
CPE | cpe:2.3:h:copeland:site_supervisor_cx_860-1260:-:*:*:*:*:*:*:* cpe:2.3:h:copeland:site_supervisor_bxe_860-1245:-:*:*:*:*:*:*:* cpe:2.3:h:copeland:site_supervisor_rx_860-1220:-:*:*:*:*:*:*:* cpe:2.3:h:copeland:site_supervisor_sf_860-1200:-:*:*:*:*:*:*:* cpe:2.3:h:copeland:site_supervisor_rxe_860-1225:-:*:*:*:*:*:*:* cpe:2.3:h:copeland:site_supervisor_bx_860-1240:-:*:*:*:*:*:*:* cpe:2.3:h:copeland:site_supervisor_cxe_860-1265:-:*:*:*:*:*:*:* cpe:2.3:o:copeland:e3_supervisory_controller_firmware:*:*:*:*:*:*:*:* |
02 Sep 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-02 12:15
Updated : 2025-10-01 18:25
NVD link : CVE-2025-52548
Mitre link : CVE-2025-52548
CVE.ORG link : CVE-2025-52548
JSON object : View
Products Affected
copeland
- site_supervisor_bx_860-1240
- site_supervisor_bxe_860-1245
- site_supervisor_rxe_860-1225
- site_supervisor_cx_860-1260
- e3_supervisory_controller_firmware
- site_supervisor_cxe_860-1265
- site_supervisor_sf_860-1200
- site_supervisor_rx_860-1220
CWE
CWE-1242
Inclusion of Undocumented Features or Chicken Bits