CVE-2024-9441: Linear eMerge e3-Series Forgot Password Command Injection
The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the loginid parameter when invoking the forgotpassword functionality over HTTP.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9441?
CVE-2024-9441 is rated as a high severity vulnerability due to the potential for remote code execution by unauthenticated attackers.
How do I fix CVE-2024-9441?
To fix CVE-2024-9441, upgrade to a version of Linear eMerge e3-Series that is later than version 1.00-07 that addresses this vulnerability.
What type of vulnerability is CVE-2024-9441?
CVE-2024-9441 is an OS command injection vulnerability that allows attackers to execute arbitrary commands.
Can CVE-2024-9441 be exploited remotely?
Yes, CVE-2024-9441 can be exploited remotely over HTTP without requiring authentication.
Which versions of the Linear eMerge e3-Series are affected by CVE-2024-9441?
CVE-2024-9441 affects all versions of Linear eMerge e3-Series up to and including version 1.00-07.