{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-52548","assignerOrgId":"dd59f033-460c-4b88-a075-d4d3fedb6191","state":"PUBLISHED","assignerShortName":"Armis","dateReserved":"2025-06-17T17:29:21.841Z","datePublished":"2025-09-02T11:26:08.636Z","dateUpdated":"2025-09-02T13:28:08.207Z"},"containers":{"cna":{"affected":[{"defaultStatus":"affected","product":"E3 Supervisory Control","vendor":"Copeland LP","versions":[{"lessThan":"2.31F01","status":"affected","version":"0","versionType":"firmware"}]}],"credits":[{"lang":"en","type":"finder","value":"Armis Labs"}],"datePublic":"2025-07-29T12:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"E3 Site Supervisor Control (firmware version &lt; 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS."}],"value":"E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS."}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.9,"baseSeverity":"MEDIUM","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-1242","description":"CWE-1242","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"dd59f033-460c-4b88-a075-d4d3fedb6191","shortName":"Armis","dateUpdated":"2025-09-02T11:26:08.636Z"},"references":[{"url":"https://www.armis.com/research/frostbyte10/"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Upgrade firmware of affected E3 Supervisory Controls to a version &gt; 2.30F1.<br>"}],"value":"Upgrade firmware of affected E3 Supervisory Controls to a version > 2.30F1."}],"source":{"discovery":"UNKNOWN"},"title":"Enabling SSH and Shellinabox on the vulnerable machine","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Restrict access to the E3 Supervisory Controls network interface (ETH 0) by use of restricted VLAN or subnet and / or network firewall. Ensure the restricted VLAN or subnet is never accessible from untrusted networks."}],"value":"Restrict access to the E3 Supervisory Controls network interface (ETH 0) by use of restricted VLAN or subnet and / or network firewall. Ensure the restricted VLAN or subnet is never accessible from untrusted networks."}],"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-09-02T13:27:58.507057Z","id":"CVE-2025-52548","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-09-02T13:28:08.207Z"}}]}}