E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can access any file from the E3 file system.

Project Subscriptions

Vendors Products
Copeland Subscribe
E3 Supervisory Controller Firmware Subscribe
Site Supervisor Bx 860-1240 Subscribe
Site Supervisor Bxe 860-1245 Subscribe
Site Supervisor Cx 860-1260 Subscribe
Site Supervisor Cxe 860-1265 Subscribe
Site Supervisor Rx 860-1220 Subscribe
Site Supervisor Rxe 860-1225 Subscribe
Site Supervisor Sf 860-1200 Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2025-26399 E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can access any file from the E3 file system.
Fixes

Solution

Upgrade firmware of affected E3 Supervisory Controls to a version > 2.30F1.


Workaround

Restrict access to the E3 Supervisory Controls network interface (ETH 0) by use of restricted VLAN or subnet and / or network firewall. Ensure the restricted VLAN or subnet is never accessible from untrusted networks.

History

Wed, 01 Oct 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Copeland
Copeland e3 Supervisory Controller Firmware
Copeland site Supervisor Bx 860-1240
Copeland site Supervisor Bxe 860-1245
Copeland site Supervisor Cx 860-1260
Copeland site Supervisor Cxe 860-1265
Copeland site Supervisor Rx 860-1220
Copeland site Supervisor Rxe 860-1225
Copeland site Supervisor Sf 860-1200
CPEs cpe:2.3:h:copeland:site_supervisor_bx_860-1240:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_bxe_860-1245:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_cx_860-1260:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_cxe_860-1265:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_rx_860-1220:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_rxe_860-1225:-:*:*:*:*:*:*:*
cpe:2.3:h:copeland:site_supervisor_sf_860-1200:-:*:*:*:*:*:*:*
cpe:2.3:o:copeland:e3_supervisory_controller_firmware:*:*:*:*:*:*:*:*
Vendors & Products Copeland
Copeland e3 Supervisory Controller Firmware
Copeland site Supervisor Bx 860-1240
Copeland site Supervisor Bxe 860-1245
Copeland site Supervisor Cx 860-1260
Copeland site Supervisor Cxe 860-1265
Copeland site Supervisor Rx 860-1220
Copeland site Supervisor Rxe 860-1225
Copeland site Supervisor Sf 860-1200
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 02 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Sep 2025 11:30:00 +0000

Type Values Removed Values Added
Description E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can access any file from the E3 file system.
Title Arbitrary read file from the filesystem
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Armis

Published:

Updated: 2025-09-02T13:36:13.634Z

Reserved: 2025-06-17T17:29:21.841Z

Link: CVE-2025-52544

cve-icon Vulnrichment

Updated: 2025-09-02T13:35:09.916Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-02T12:15:36.677

Modified: 2025-10-01T18:27:30.030

Link: CVE-2025-52544

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses