Description Preview
Overview
The vulnerability is an instance of insufficiently protected credentials (CWE-522) where a fixed administrative account with an algorithmically predictable daily password exposes supervisory control interfaces to trivial remote compromise. A remote attacker on the same network segment (or any segment with access to the device's ETH0 interface) can derive the ONEDAY password and obtain administrative control. The ONEDAY account cannot be deleted or modified through normal user operations, preventing mitigation by removing the account. The issue affects Copeland LP E3 Supervisory Control firmware versions older than 2.31F01 and is credited to Armis Labs.
Remediation
Upgrade affected E3 Supervisory Control firmware to a fixed release (2.31F01 or later) as provided by the vendor. If immediate upgrade is not possible, restrict access to the device management network by isolating the E3 supervisory interface (ETH0) on a trusted VLAN or subnet and block access from untrusted networks using network firewall rules. Ensure the management VLAN/subnet is never reachable from general-purpose or internet-connected networks, monitor for unexpected administrative logins, and apply firmware updates as soon as they are available.
References
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Accommodation & Food ServicesAccommodation & Food Services: Low
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services: Low
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting: Low
- Arts, Entertainment & RecreationArts, Entertainment & Recreation: Low
- ConstructionConstruction: Low
- Educational ServicesEducational Services: Low
- Finance and InsuranceFinance and Insurance: Low
- Health Care & Social AssistanceHealth Care & Social Assistance: Low
- InformationInformation: Low
- Management of Companies & EnterprisesManagement of Companies & Enterprises: Low
- ManufacturingManufacturing: Low
- MiningMining: Low
- Other Services (except Public Administration)Other Services (except Public Administration): Low
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services: Low
- Public AdministrationPublic Administration: Low
- Real Estate Rental & LeasingReal Estate Rental & Leasing: Low
- Retail TradeRetail Trade: Low
- Transportation & WarehousingTransportation & Warehousing: Low
- UtilitiesUtilities: Low
- Wholesale TradeWholesale Trade: Low