CVE-2025-52543
E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An attacker can authenticate by obtaining only the password hash.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:L/SA:L
- EPSS probability
- 0.30%
- CWE
- CWE-836
- Published
- 2025-09-02
- Last modified
- 2026-03-13
Affected products
- Copeland LP E3 Supervisory Control
Weakness type
Related vulnerabilities
- CVE-2026-44736 — OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects
- CVE-2026-9222 — Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication
- CVE-2026-40103 — Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds
- CVE-2019-25552 — CEWE PHOTO SHOW 6.4.3 Denial of Service via Password Field
- CVE-2025-64471 — A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability...
- CVE-2025-62618 — ELOG file upload stored XSS
- CVE-2025-48925 — The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do...
- CVE-2023-39546 — CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe...