nortekcontrol Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with nortekcontrol products.
Products
- emerge_e3_firmware2 vulnerabilities
- linear_emerge_essential_firmware2 vulnerabilities
- linear_emerge_elite_firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-9441CRITICAL | Linear eMerge e3-Series Forgot Password Command InjectionThe Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP. CWE-78Oct 2, 2024 | CVSS9.8v3.1 | EPSS53.5% | PoCs3 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-31499CRITICAL | nortekcontrol emerge_e3_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256. | CVSS9.8v3.1 | EPSS64.6% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2019-7254HIGH | nortekcontrol linear_emerge_essential_firmware Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Linear eMerge E3-Series devices allow File Inclusion. | CVSS7.5v3.1 | EPSS82.3% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2019-7256CRITICAL | Nice Linear eMerge E3-Series OS Command Injection VulnerabilityLinear eMerge E3-Series devices allow Command Injections. | CVSS9.8v3.1 | EPSS97.1% | PoCs2 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |