CVE-2024-9441
CVE-2024-9441
9.8
CriticalPublished:
Last updated:
Source:disclosure@vulncheck.com
Deferred
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Description
The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.
References
disclosure@vulncheck.com
https://ssd-disclosure.com/ssd-advisory-nortek-linear-emerge-e3-pre-auth-rce/disclosure@vulncheck.com
https://vulncheck.com/advisories/linear-emerge-forgot-password