CVE-2019-7256
Nice Linear eMerge E3-Series OS Command Injection Vulnerability
Severity Score
10.0
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
9
*Multiple Sources
Exploited in Wild
Yes
*KEV
Decision
Act
*SSVC
Descriptions
Linear eMerge E3-Series devices allow Command Injections.
Los dispositivos Linear eMerge E3-Series permiten Inyecciones de Comando.
Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Act
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-01-31 CVE Reserved
- 2019-07-02 CVE Published
- 2019-11-12 First Exploit
- 2024-03-25 Exploited in Wild
- 2024-04-15 KEV Due Date
- 2024-08-04 CVE Updated
- 2025-01-01 EPSS Updated
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
https://applied-risk.com/labs/advisories | Not Applicable | |
https://www.applied-risk.com/resources/ar-2019-005 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nortekcontrol Search vendor "Nortekcontrol" | Linear Emerge Essential Firmware Search vendor "Nortekcontrol" for product "Linear Emerge Essential Firmware" | <= 1.00-06 Search vendor "Nortekcontrol" for product "Linear Emerge Essential Firmware" and version " <= 1.00-06" | - |
Affected
| in | Nortekcontrol Search vendor "Nortekcontrol" | Linear Emerge Essential Search vendor "Nortekcontrol" for product "Linear Emerge Essential" | - | - |
Safe
|
Nortekcontrol Search vendor "Nortekcontrol" | Linear Emerge Elite Firmware Search vendor "Nortekcontrol" for product "Linear Emerge Elite Firmware" | <= 1.00-06 Search vendor "Nortekcontrol" for product "Linear Emerge Elite Firmware" and version " <= 1.00-06" | - |
Affected
| in | Nortekcontrol Search vendor "Nortekcontrol" | Linear Emerge Elite Search vendor "Nortekcontrol" for product "Linear Emerge Elite" | - | - |
Safe
|