Record summary

CVE-2022-31499 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 12, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubomarhashem123/CVE-2022-31499Repository PoCby omarhashem123Stars: 1Not analyzed2 files

650 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALNortek Linear eMerge E3-Series <0.32-08f - Remote Command InjectionCVSS 9.8

Nortek Linear eMerge E3-Series devices before 0.32-08f are susceptible to remote command injection via ReaderNo. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-7256.

Impact

Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected system.

Remediation

Upgrade to a patched version of Nortek Linear eMerge E3-Series (>=0.32-08f) to mitigate this vulnerability.

WeaknessesCWE-78
Authorspikpikcu
Template tagstime-based-sqlicvecve2022packetstormemergercenortekcontrolvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:nortekcontrol:emerge_e3_firmware:*:*:*:*:*:*:*:*
Shodan: title:"eMerge"
Shodan: http.title:"emerge"
Shodan: http.title:"linear emerge"
FOFA: title="emerge"
FOFA: title="linear emerge"
Google: intitle:"linear emerge"
Google: intitle:"emerge"

Source: ProjectDiscovery

References

4