|
|||
Rule General Information |
---|
Release Date: | 2024-12-31 | |
Rule Name: | Linear eMerge e3-Series Command Injection Vulnerability (CVE-2024-9441) | |
Severity: | Critical | |
CVE ID: | CVE-2024-9441 | |
Rule Protection Details |
---|
Description: | The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP. | |
Impact: | An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software. | |
Affected OS: | Windows, Linux, Others | |
Reference: | https://ssd-disclosure.com/ssd-advisory-nortek-linear-emerge-e3-pre-auth-rce/ https://vulncheck.com/advisories/linear-emerge-forgot-password |
|
Solutions |
---|
Please contact the software vendor to update the software patch. |