CVE-2025-52551 describes a critical vulnerability in E2 Facility Management Systems, allowing unauthenticated file operations on any file within the system due to a flaw in its proprietary protocol. This vulnerability carries a CVSS score of 9.3 (CRITICAL), indicating a network-based attack with low complexity and no user interaction required, leading to high impact on confidentiality, integrity, and availability. While there is no known active exploitation or publicly available exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, including a warning from CSO Online.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Copeland LP | E2 Facility Management System | >= 0, <= <=4.11F02CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.