CRITICAL
Linear eMerge e3-Series Forgot Password Command Injection
Published Oct 2, 2024
9.8
CRITICALCVSS 3.1
EPSS 53.47%
Description
The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.
Affected products
-
- Version 0StatusaffectedConstraints<=1.00-07
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Linear | eMerge e3-Series | unaffected |
|
No data.
-
- Version 0StatusaffectedConstraints<=1.00-07
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Nortekcontrol | Emerge E3 Firmware | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://ssd-disclosure.com/ssd-advisory-nortek-linear-emerge-e3-pre-auth-rce/ vendor-advisoryexploit
- https://vulncheck.com/advisories/linear-emerge-forgot-password third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://ssd-disclosure.com/ssd-advisory-nortek-linear-emerge-e3-pre-auth-rce/ | vendor-advisoryexploit | |
| https://vulncheck.com/advisories/linear-emerge-forgot-password | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Oct 2, 2024
Updated Oct 2, 2024
Reserved Oct 2, 2024
Link CVE-2024-9441
CISA Vulnrichment
Updated Oct 2, 2024