CVE-2022-31269: High severity nortek control emerge e3 vulnerability
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31269?
CVE-2022-31269 has a high severity due to its potential for unauthorized access to building security controls.
How do I fix CVE-2022-31269?
To fix CVE-2022-31269, ensure that admin credentials are securely stored and not placed in accessible files like /test.txt.
Which devices are affected by CVE-2022-31269?
CVE-2022-31269 affects Nortek Linear eMerge E3-Series devices running firmware versions up to 0.32-09c.
What kind of attack can be performed using CVE-2022-31269?
An attacker can exploit CVE-2022-31269 to gain unauthorized access to building doors if they obtain admin credentials.
Are default credentials related to CVE-2022-31269?
Yes, CVE-2022-31269 is relevant in scenarios where the default credentials have been changed from those outlined in CVE-2019-7271.