Description Preview
Overview
Affected devices are Copeland LP E3 Supervisory Controls running firmware versions less than 2.31F01. The vulnerability manifests as predictable root password generation on each boot, which an attacker with network access to the device can reproduce using publicly available or easily obtained device parameters. Attack complexity is low, no privileges are required, and exploitation can be automated to obtain persistent root access and control over the affected device and potentially the OT network it serves.
Remediation
Update affected E3 Supervisory Controls to a fixed firmware version (upgrade to a version > 2.30F1 as provided by the vendor). If immediate upgrade is not possible, restrict access to the device management network interface (ETH 0) by placing devices on a restricted VLAN or subnet and enforcing network firewall rules so the interface is never reachable from untrusted networks. After patching, rotate root credentials and any related keys or secrets, verify device integrity and logs for unauthorized access, and apply network segmentation, monitoring, and least-privilege controls to reduce exposure.
References
- Armis Labs — Frostbyte 10 research: https://www.armis.com/research/frostbyte10/
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Accommodation & Food ServicesAccommodation & Food Services: Low
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services: Low
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting: Low
- Arts, Entertainment & RecreationArts, Entertainment & Recreation: Low
- ConstructionConstruction: Low
- Educational ServicesEducational Services: Low
- Finance and InsuranceFinance and Insurance: Low
- Health Care & Social AssistanceHealth Care & Social Assistance: Low
- InformationInformation: Low
- Management of Companies & EnterprisesManagement of Companies & Enterprises: Low
- ManufacturingManufacturing: Low
- MiningMining: Low
- Other Services (except Public Administration)Other Services (except Public Administration): Low
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services: Low
- Public AdministrationPublic Administration: Low
- Real Estate Rental & LeasingReal Estate Rental & Leasing: Low
- Retail TradeRetail Trade: Low
- Transportation & WarehousingTransportation & Warehousing: Low
- UtilitiesUtilities: Low
- Wholesale TradeWholesale Trade: Low