Vulnerability Description
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nortekcontrol | Emerge E3 Firmware | <= 0.32-09c |
| Nortekcontrol | Emerge E3 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/167990/Nortek-Linear-eMerge-E3-Series-CredeExploitThird Party AdvisoryVDB Entry
- https://eg.linkedin.com/in/omar-1-hashemNot Applicable
- https://gist.github.com/omarhashem123/71ec9223e90ea76a76096d777d9b945cExploitThird Party Advisory
- https://www.nortekcontrol.com/access-control/Product
- http://packetstormsecurity.com/files/167990/Nortek-Linear-eMerge-E3-Series-CredeExploitThird Party AdvisoryVDB Entry
- https://eg.linkedin.com/in/omar-1-hashemNot Applicable
- https://gist.github.com/omarhashem123/71ec9223e90ea76a76096d777d9b945cExploitThird Party Advisory
- https://www.nortekcontrol.com/access-control/Product
FAQ
What is CVE-2022-31269?
CVE-2022-31269 is a vulnerability with a CVSS score of 8.2 (HIGH). Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 defau...
How severe is CVE-2022-31269?
CVE-2022-31269 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31269?
Check the references section above for vendor advisories and patch information. Affected products include: Nortekcontrol Emerge E3 Firmware, Nortekcontrol Emerge E3.