CVE-2022-38628: XSS
Published Dec 13, 2022
·Updated
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a cross-site scripting (XSS) vulnerability which is chained with a local session fixation. This vulnerability allows attackers to escalate privileges via unspecified vectors.
Affected Software
16 affected components
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-07e
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-07p
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-08e
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-08f
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-09a
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-09b
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-09c
Niceforyou Linear Emerge E3 Access Control
All of the following
Any of the following
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-07e
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-07p
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-08e
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-08f
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-09a
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-09b
Niceforyou Linear Emerge E3 Access Control Firmware=0.32-09c
Niceforyou Linear Emerge E3 Access Control
Event History
Dec 13, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-38628?
The severity of CVE-2022-38628 is rated as medium with a CVSS score of 6.1.
2
How can I exploit CVE-2022-38628?
Attackers can exploit CVE-2022-38628 to escalate privileges via unspecified vectors by leveraging the cross-site scripting vulnerability chained with a local session fixation.
3
Is Niceforyou Linear Emerge E3 Access Control Firmware 0.32-09c affected by CVE-2022-38628?
Yes, Niceforyou Linear Emerge E3 Access Control Firmware version 0.32-09c is affected by CVE-2022-38628.
4
What is the Common Vulnerabilities and Exposures ID for this vulnerability?
The Common Vulnerabilities and Exposures ID for this vulnerability is CVE-2022-38628.