High severity7.2NVD Advisory· Published Sep 2, 2025· Updated Jun 17, 2026
CVE-2025-52550
CVE-2025-52550
Description
E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin access to the application services can install a malicious firmware upgrade.
Affected products
2- cpe:2.3:o:copeland:e3_supervisory_controller_firmware:*:*:*:*:*:*:*:*Range: <2.31f01
- Copeland LP/E3 Supervisory Controlv5Range: 0
Patches
Vulnerability mechanics
References
1- www.armis.com/research/frostbyte10/nvdMitigationThird Party Advisory
News mentions
0No linked articles in our index yet.