CVE-2022-31798: XSS
Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /cardscan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31798?
CVE-2022-31798 is considered a high severity vulnerability due to its potential to allow attackers to take over admin or user accounts.
How does CVE-2022-31798 exploit the Nortek Linear eMerge E3-Series devices?
CVE-2022-31798 exploits the devices through a cross-site scripting vulnerability combined with session fixation in the card scanning endpoint.
What versions of the Nortek Emerge E3 firmware are affected by CVE-2022-31798?
The affected versions of Nortek Emerge E3 firmware are up to and including version 0.32-07p.
Can CVE-2022-31798 affect user account security?
Yes, CVE-2022-31798 can compromise user account security by allowing attackers to take over accounts using session fixation.
What should users of Nortek Emerge E3 devices do regarding CVE-2022-31798?
Users should update their devices to the latest firmware version that addresses CVE-2022-31798 to mitigate the risks.