Nortek Linear eMerge E3 Series CVE-2017-5439 Remote Command Injection Vulnerability
BID:103053
CVE-2017-5439 |Info
Nortek Linear eMerge E3 Series CVE-2017-5439 Remote Command Injection Vulnerability
| Bugtraq ID: | 103053 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-5439 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2018 12:00AM |
| Updated: | Feb 15 2018 12:00AM |
| Credit: | Evgeny Ermakov and Sergey Gordeychik |
| Vulnerable: |
Nortek Linear eMerge E3 Series 0.32-07e |
| Not Vulnerable: | |
Discussion
Nortek Linear eMerge E3 Series CVE-2017-5439 Remote Command Injection Vulnerability
Nortek Linear eMerge E3 Series is prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary command within the context of user running the affected application. Failed exploit attempts may result in a denial-of-service condition.
Nortek Linear eMerge E3 Series versions V0.32-07e and prior are vulnerable.
Nortek Linear eMerge E3 Series is prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary command within the context of user running the affected application. Failed exploit attempts may result in a denial-of-service condition.
Nortek Linear eMerge E3 Series versions V0.32-07e and prior are vulnerable.
Exploit / POC
Nortek Linear eMerge E3 Series CVE-2017-5439 Remote Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Nortek Linear eMerge E3 Series CVE-2017-5439 Remote Command Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Nortek Linear eMerge E3 Series CVE-2017-5439 Remote Command Injection Vulnerability
References:
References:
- Nortek Homepage (Nortek)
- ICSA-18-046-01: Nortek Linear eMerge E3 Series (ICS CERT)