Experts Warn of Critical Unpatched Vulnerability in Linear eMerge E3 Systems
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-7256 | Unauthenticated OS Command Injection in Nice Linear eMerge E3 Access Controllers CVE-2019-7256 is a critical (CVSS 9.8) unauthenticated OS command injection flaw (CWE-78) in the web interface of Nice/Nortek Control Linear eMerge E3-Series access control controllers. An unauthenticated remote attacker can send crafted HTTP requests to the controller's web endpoints — public proofs of concept target card_scan.php and card_scan_decoder.php on firmware 1.00-06 — causing arbitrary operating-system commands to run on the device. Successful exploitation yields full command execution on the controller, enabling takeover of the building access system and, as observed in the wild, conscription of exposed devices into DDoS botnets. Any site running Linear eMerge E3-Series Essential or Elite firmware is affected, especially controllers directly reachable from the internet. Exploitation is confirmed: public PoCs date to 2019, the bug was added to CISA's KEV catalog on 2024-03-25 amid reported active exploitation, and EPSS assigns a 97.1% probability of exploitation within 30 days (100th percentile). Do: Remove E3-Series controllers from direct internet exposure (restrict the web interface to management networks or VPN) and check exposed devices for signs of botnet compromise, such as unusual outbound traffic. Because CISA's required action is to remediate firmware per the vendor advisory, contact Nice/Nortek Control for current firmware and remediation guidance, and treat the flaw as actively exploited given the KEV listing and 97.1% EPSS. | 9.8 | 97% | KEV PoC ×4 |
| moderatelow thousands of internet-exposed E3 controllers; installed base plausibly in the tens of thousands across commercial sites | |
| CVE-2024-9441 | Unauthenticated OS Command Injection in Linear eMerge e3-Series Access Controllers CVE-2024-9441 is a critical OS command injection flaw (CWE-78) in Linear eMerge e3-Series access control controllers running version 1.00-07 and earlier. An unauthenticated remote attacker can send a crafted HTTP request to the forgot_password functionality, injecting arbitrary OS commands through the login_id parameter, which the controller then executes. Successful exploitation yields full command execution on the device, allowing the attacker to compromise the controller, access or alter credentials, and potentially pivot into the building's access control environment or the connected network. Any organization running an eMerge e3-Series controller at or below version 1.00-07 is affected, particularly units with their web interface reachable from the internet. As of disclosure, there is no known public proof-of-concept and the flaw is not in CISA KEV, but the high EPSS score (53.5%, 99th percentile) indicates an elevated likelihood of exploitation attempts within 30 days. Do: The headline reporting indicates the flaw is currently unpatched, so until Linear/Nortek ships a fix for versions beyond 1.00-07, restrict the controller's web interface to trusted management networks via firewall rules or VPN and avoid exposing the forgot_password endpoint to the internet. Check HTTP access logs for requests to the forgot_password functionality containing shell metacharacters or unexpected values in the login_id parameter, and monitor for anomalous commands on the device. Apply the vendor firmware update as soon as one becomes available. | 9.8 | 53% |
| largetens of thousands of deployed controllers (order of 10^4), with only a few thousand likely internet-exposed |
Full article303 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 10, 2024Vulnerability / Enterprise Security
Cybersecurity researchers are warning about an unpatched vulnerability in Nice Linear eMerge E3 access controller systems that could allow for the execution of arbitrary operating system (OS) commands.
The flaw, assigned the CVE identifier CVE-2024-9441, carries a CVSS score of 9.8 out of a maximum of 10.0, according to VulnCheck.
"A vulnerability in the Nortek Linear eMerge E3 allows remote unauthenticated attackers to cause the device to execute arbitrary command," SSD Disclosure said in an advisory for the flaw released late last month, stating the vendor has yet to provide a fix or a workaround.
The flaw impacts the following versions of Nortek Linear eMerge E3 Access Control: 0.32-03i, 0.32-04m, 0.32-05p, 0.32-05z, 0.32-07p, 0.32-07e, 0.32-08e, 0.32-08f, 0.32-09c, 1.00.05, and 1.00.07.
Proof-of-concept (PoC) exploits for the flaw have been released following public disclosure, raising concerns that it could be exploited by threat actors.
It's worth noting that another critical flaw impacting E3, CVE-2019-7256 (CVSS score: 10.0), was exploited by a threat actor known as Flax Typhoon to recruit susceptible devices into the now-dismantled Raptor Train botnet.
Although originally disclosed in May 2019, the shortcoming wasn't addressed by the company until earlier this March.
"But given the vendor's slow response to the previous CVE-2019-7256, we don’t expect a patch for CVE-2024-9441 any time soon," VulnCheck's Jacob Baines said. "Organizations using the Linear Emerge E3 series should act quickly to take these devices offline or isolate them."
In a statement shared with SSD Disclosure, Nice is recommending customers to follow security best practices, including enforcing network segmentation, restricting access to the product from the internet, and placing it behind a network firewall.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/10/experts-warn-of-critical-unpatched.html