CVE-2022-38627: SQL Injection
Published Jan 3, 2023
·Updated
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.
Affected Software
7 affected components
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-07e
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-07p
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-08e
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-08f
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-09a
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-09c
Niceforyou Linear Emerge E3 Access Control
Event History
Jan 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-38627?
The severity of CVE-2022-38627 is rated as critical with a CVSS score of 9.8.
2
What software versions of Nortek Linear eMerge E3-Series are affected by CVE-2022-38627?
The affected versions of Nortek Linear eMerge E3-Series include 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e.
3
How does CVE-2022-38627 vulnerability occur?
CVE-2022-38627 vulnerability occurs through a SQL injection via the idt parameter in Nortek Linear eMerge E3-Series.