logo

Frostbyte10 bugs put thousands of refrigerators at major grocery chains at risk

ID: 647ed2f4-d04e-54ab-8902-fe073f686c1c

STIX ID: report--647ed2f4-d04e-54ab-8902-fe073f686c1c

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-09-02

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Armis disclosed Frostbyte10 — ten vulnerabilities in Copeland E2/E3 refrigeration and facility controllers used by major retailers and cold-storage companies. Several bugs are high/critical (including predictable admin credentials, arbitrary read, privilege escalation, DoS, and unsigned firmware/package issues) and can be chained to achieve unauthenticated RCE with root privileges, risking food and medicine spoilage and supply-chain disruption. Copeland released firmware fixes (E3 version 2.31F01) and recommends urgent patching; E2 devices are at end-of-life. There is no indication the flaws were exploited in the wild prior to disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.