nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-52543 CVE-2025-52543
MEDIUM
Login to the application services using only the password hash
Record summary
CVE-2025-52543 has a selected CVSS score of 5.3 (medium).
Description
E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An attacker can authenticate by obtaining only the password hash.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 2, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
E3 Supervisory ControlBrowse Copeland LP / E3 Supervisory ControlDefault status: affected | CVE List | Before 2.31F01 | affected |
References
2armis.com
https://www.armis.com/research/frostbyte10