CVE-2025-52543
HIGHDescription
E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An attacker can authenticate by obtaining only the password hash.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| copeland | e3_supervisory_controller_firmware |
| copeland | site_supervisor_bx_860-1240 |
| copeland | site_supervisor_bxe_860-1245 |
| copeland | site_supervisor_cx_860-1260 |
| copeland | site_supervisor_cxe_860-1265 |
| copeland | site_supervisor_rx_860-1220 |
| copeland | site_supervisor_rxe_860-1225 |
| copeland | site_supervisor_sf_860-1200 |
References
Other References
Frequently Asked Questions
What is CVE-2025-52543? +
How severe is CVE-2025-52543? +
What products are affected by CVE-2025-52543? +
How do I check if I'm vulnerable to CVE-2025-52543? +
Related Vulnerabilities
ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other …
A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb …
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and …
E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate …
E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker …
E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to …