CVE-2022-31499: OS Command Injection
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31499?
CVE-2022-31499 is considered a high severity vulnerability due to the potential for unauthenticated command injection.
How do I fix CVE-2022-31499?
To mitigate CVE-2022-31499, update the Nortek Linear eMerge E3-Series devices to firmware version 0.32-08f or later.
What type of vulnerability is CVE-2022-31499?
CVE-2022-31499 is a command injection vulnerability that allows attackers to execute OS commands on the affected device.
Which devices are affected by CVE-2022-31499?
CVE-2022-31499 affects Nortek Linear eMerge E3-Series devices running firmware versions prior to 0.32-08f.
Is CVE-2022-31499 linked to any previous vulnerabilities?
Yes, CVE-2022-31499 is related to CVE-2019-7256, which had an incomplete fix allowing this command injection vulnerability to persist.