CISA Known Exploited Vulnerability (KEV)
Nice Linear eMerge E3-Series OS Command Injection Vulnerability
March 25, 2024
April 15, 2024
Contact the vendor for guidance on remediating firmware, per their advisory.
Description
Linear eMerge E3-Series devices allow Command Injections.
References
- http://packetstormsecurity.com/files/155255/Linear-eMerge-E3-1.00-06-card_scan.php-Command-Injection.html
- http://packetstormsecurity.com/files/155256/Linear-eMerge-E3-1.00-06-card_scan_decoder.php-Command-Injection.html
- http://packetstormsecurity.com/files/155272/Linear-eMerge-E3-Access-Controller-Command-Injection.html
- http://packetstormsecurity.com/files/170372/Linear-eMerge-E3-Series-Access-Controller-Command-Injection.html
- https://applied-risk.com/labs/advisories
- https://www.applied-risk.com/resources/ar-2019-005
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-78 |
Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) |