Vulnerability Description
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nortekcontrol | Emerge E3 Firmware | <= 0.32-09c |
| Nortekcontrol | Emerge E3 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/167991/Nortek-Linear-eMerge-E3-Series-CommaExploitThird Party AdvisoryVDB Entry
- https://eg.linkedin.com/in/omar-1-hashemNot Applicable
- https://gist.github.com/omarhashem123/5f0c6f1394099b555740fdc5c7651ee2ExploitThird Party Advisory
- http://packetstormsecurity.com/files/167991/Nortek-Linear-eMerge-E3-Series-CommaExploitThird Party AdvisoryVDB Entry
- https://eg.linkedin.com/in/omar-1-hashemNot Applicable
- https://gist.github.com/omarhashem123/5f0c6f1394099b555740fdc5c7651ee2ExploitThird Party Advisory
FAQ
What is CVE-2022-31499?
CVE-2022-31499 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.
How severe is CVE-2022-31499?
CVE-2022-31499 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-31499?
Check the references section above for vendor advisories and patch information. Affected products include: Nortekcontrol Emerge E3 Firmware, Nortekcontrol Emerge E3.