vendor:
eMerge E3
by:
LiquidWorm
10
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: eMerge E3
Affected Version From: 1.00-06
Affected Version To: 1.00-06
Patch Exists: NO
Related CWE: CVE-2019-7256
CPE: linear:emerge_e3:1.00-06
Tags: cve,cve2019,emerge,rce,edb
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Nuclei Metadata: {'max-request': 2, 'verified': True, 'shodan-query': 'title:"eMerge"', 'vendor': 'nortekcontrol', 'product': 'linear_emerge_essential_firmware'}
Platforms Tested:
2019
Linear eMerge E3 1.00-06 – Remote Code Execution
This exploit allows an attacker to execute remote code on the Linear eMerge E3 version 1.00-06. It is achieved through an unauthenticated command injection vulnerability in the card_scan_decoder.php file. The vulnerability is identified by the CVE-2019-7256 identifier. The exploit provides an example of obtaining web front-end credentials and escalating privileges to root. The affected version is <=1.00-06.
Mitigation:
Apply the vendor's security patch to fix the vulnerability.