CVE CVE

CVE-2019-7256

CISA Known Exploited Vulnerability (KEV)

Nice Linear eMerge E3-Series OS Command Injection Vulnerability

March 25, 2024

April 15, 2024

Contact the vendor for guidance on remediating firmware, per their advisory.

Description

Linear eMerge E3-Series devices allow Command Injections.

Weakness Enumeration

CWE-ID CWE Name

CWE-78
Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
10
Severity:

CRITICAL

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS v2

Base score:
10
Severity:

HIGH

Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C