CVE-2019-7262: CSRF
Published Jul 2, 2019
·Updated
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
Affected Software
4 affected components
Nortekcontrol Linear Emerge Essential Firmware<=1.00-06
Nortekcontrol Linear Emerge Essential
Nortekcontrol Linear Emerge Elite Firmware<=1.00-06
Nortekcontrol Linear Emerge Elite
Event History
Jul 2, 2019
CVE Published
via MITRE·05:01 PM
Data Sourced
via MITRE·05:01 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-7262?
CVE-2019-7262 is classified as a moderate severity vulnerability due to the potential for unauthorized actions via Cross-Site Request Forgery.
2
How do I fix CVE-2019-7262?
To mitigate CVE-2019-7262, update to the latest version of the Linear Emerge Essential or Elite firmware that addresses this vulnerability.
3
What types of devices are affected by CVE-2019-7262?
CVE-2019-7262 affects Linear Emerge E3-Series devices, specifically those running vulnerable versions of Essential and Elite firmware.
4
What attack vector is exploited in CVE-2019-7262?
CVE-2019-7262 exploits Cross-Site Request Forgery (CSRF), allowing an attacker to perform actions on behalf of a user without their consent.
5
Is my device vulnerable if it uses Linear Emerge firmware version higher than 1.00-06 for CVE-2019-7262?
No, devices using Linear Emerge firmware versions above 1.00-06 are not vulnerable to CVE-2019-7262.