CVE-2022-31499
nortekcontrol emerge_e3_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2022-31499 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
emerge_e3_firmwareBrowse nortekcontrol / emerge_e3_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubomarhashem123/CVE-2022-31499Repository PoCby omarhashem123Stars: 1Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALNortek Linear eMerge E3-Series <0.32-08f - Remote Command InjectionCVSS 9.8
Nortek Linear eMerge E3-Series devices before 0.32-08f are susceptible to remote command injection via ReaderNo. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-7256.
Impact
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected system.
Remediation
Upgrade to a patched version of Nortek Linear eMerge E3-Series (>=0.32-08f) to mitigate this vulnerability.
Source: ProjectDiscovery