Описание
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Not Applicable
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- Not Applicable
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.32-09c (включая)
Одновременно
cpe:2.3:o:nortekcontrol:emerge_e3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nortekcontrol:emerge_e3:-:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.92506
Критический
9.8 Critical
CVSS3
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.
EPSS
Процентиль: 100%
0.92506
Критический
9.8 Critical
CVSS3
Дефекты
CWE-78