9.8
CVSSv3

CVE-2022-31499

Published: 25/08/2022 Updated: 02/09/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Nortek Linear eMerge E3-Series devices prior to 0.32-08f allow an unauthenticated malicious user to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nortekcontrol emerge_e3_firmware

Vendor Advisories

Check Point Reference: CPAI-2022-2017 Date Published: 12 Feb 2024 Severity: Critical ...

Exploits

Nortek Linear eMerge E3-Series version 032-09c suffers from a blind OS command injection vulnerability ...

Github Repositories

CVE-2022-31499 Proof of Concept

CVE-2022-31499 Exploit Title: Nortek Linear eMerge E3-Series - Blind OS Command Injection