Description Preview
Overview
The vulnerability is an input-validation flaw in an MGW API that permits remote, unauthenticated actors to trigger repeated application-service crashes, producing a sustained availability impact. Affected product is Copeland LP E3 Supervisory Control firmware versions less than 2.31F01. Attack complexity is low, no privileges or user interaction are required, and the primary impact is high availability loss.
Remediation
Upgrade affected E3 Supervisory Control devices to the vendor-recommended fixed firmware release (per vendor guidance, upgrade to a version > 2.30F1). If immediate patching is not possible, restrict access to the device management/network interface (ETH 0) via segmentation (restricted VLAN or subnet) and network firewall rules, ensuring the management interface is never reachable from untrusted networks. Additionally, monitor device logs and network traffic for anomalous API calls and contact the vendor or Armis Labs for further mitigation advice.
References
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Accommodation & Food ServicesAccommodation & Food Services: Low
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services: Low
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting: Low
- Arts, Entertainment & RecreationArts, Entertainment & Recreation: Low
- ConstructionConstruction: Low
- Educational ServicesEducational Services: Low
- Finance and InsuranceFinance and Insurance: Low
- Health Care & Social AssistanceHealth Care & Social Assistance: Low
- InformationInformation: Low
- Management of Companies & EnterprisesManagement of Companies & Enterprises: Low
- ManufacturingManufacturing: Low
- MiningMining: Low
- Other Services (except Public Administration)Other Services (except Public Administration): Low
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services: Low
- Public AdministrationPublic Administration: Low
- Real Estate Rental & LeasingReal Estate Rental & Leasing: Low
- Retail TradeRetail Trade: Low
- Transportation & WarehousingTransportation & Warehousing: Low
- UtilitiesUtilities: Low
- Wholesale TradeWholesale Trade: Low