216.73.217.50

CVE-2025-52550

· Published 02/09/2025 12:15 · Modified 02/09/2025 12:15

Labels: CVE-2025-52550 2025-09-02CVE-2025-52550CWE-347dd59f033-460c-4b88-a075-d4d3fedb6191

Essential information

Published
02/09/2025 12:15
Modified
02/09/2025 12:15
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin access to the application services can install a malicious firmware upgrade.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
dd59f033-460c-4b88-a075-d4d3fedb6191
NVD
View on NVD

Affected products (CPE)

ProductCPE
* / e3 site supervisor control cpe:2.3:a:*:e3_site_supervisor_control:<2.31F01:*:*:*:*:*:*:*

References