CVE Feed

    Dashboard / CVE / CVE-2025-52550

    CVE-2025-52550

    E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin access to the application services can install a malicious firmware upgrade.

    Published:Sep 2, 2025
    Last Modified:Oct 1, 2025
    EPS:Sep 2, 2025
    EPSS Score:0.00021
    CVSS Score:7.2

    Affected Products

    Vendor
    Copeland
    Product
    E3 Supervisory Controller Firmware
    Vendor
    Copeland
    Product
    Site Supervisor Bx 860-1240
    Vendor
    Copeland
    Product
    Site Supervisor Bxe 860-1245
    Vendor
    Copeland
    Product
    Site Supervisor Cx 860-1260
    Vendor
    Copeland
    Product
    Site Supervisor Cxe 860-1265
    Vendor
    Copeland
    Product
    Site Supervisor Rx 860-1220
    Vendor
    Copeland
    Product
    Site Supervisor Rxe 860-1225
    Vendor
    Copeland
    Product
    Site Supervisor Sf 860-1200

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High