VulnerabilityModified
CVE-2022-31269
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors.
HIGH 8.2EPSS 6.99%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.99%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
- EPSS
- 6.99% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- nortekcontrol/emerge e3 firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/167990/Nortek-Linear-eMerge-E3-Series-Credential-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://eg.linkedin.com/in/omar-1-hashemNot Applicable
- https://gist.github.com/omarhashem123/71ec9223e90ea76a76096d777d9b945cExploit, Third Party Advisory
- https://www.nortekcontrol.com/access-control/Product
- http://packetstormsecurity.com/files/167990/Nortek-Linear-eMerge-E3-Series-Credential-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://eg.linkedin.com/in/omar-1-hashemNot Applicable
- https://gist.github.com/omarhashem123/71ec9223e90ea76a76096d777d9b945cExploit, Third Party Advisory
- https://www.nortekcontrol.com/access-control/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.