Known Vulnerabilities for products from Nortekcontrol
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Nortekcontrol".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-31798 json | Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via... | 6.1 - MEDIUM | 2022-08-25 | 2023-08-08 |
| CVE-2022-31499 json | Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. ... | 9.8 - CRITICAL | 2022-08-25 | 2022-09-02 |
| CVE-2022-31269 json | Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a... | 8.2 - HIGH | 2022-08-25 | 2022-09-02 |
| CVE-2019-7271 json | Nortek Linear eMerge 50P/5000P devices have Default Credentials. | 9.8 - CRITICAL | 2019-07-01 | 2020-08-24 |
| CVE-2019-7270 json | Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF). | 8.8 - HIGH | 2019-07-02 | 2022-10-14 |
| CVE-2019-7269 json | Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution. | 9.8 - CRITICAL | 2019-07-02 | 2022-10-13 |
| CVE-2019-7268 json | Linear eMerge 50P/5000P devices allow Unauthenticated File Upload. | 10 - CRITICAL | 2019-07-02 | 2022-10-13 |
| CVE-2019-7267 json | Linear eMerge 50P/5000P devices allow Cookie Path Traversal. | 9.8 - CRITICAL | 2019-07-02 | 2022-10-13 |
| CVE-2019-7266 json | Linear eMerge 50P/5000P devices allow Authentication Bypass. | 9.8 - CRITICAL | 2019-07-02 | 2022-10-13 |
| CVE-2019-7265 json | Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH). | 9.8 - CRITICAL | 2019-07-02 | 2022-10-13 |
| CVE-2019-7264 json | Linear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform. | 9.8 - CRITICAL | 2019-07-02 | 2020-08-24 |
| CVE-2019-7263 json | Linear eMerge E3-Series devices have a Version Control Failure. | 9.8 - CRITICAL | 2019-07-02 | 2019-07-03 |
| CVE-2019-7262 json | Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF). | 8.8 - HIGH | 2019-07-02 | 2022-10-14 |
| CVE-2019-7261 json | Linear eMerge E3-Series devices have Hard-coded Credentials. | 9.8 - CRITICAL | 2019-07-02 | 2022-10-14 |
| CVE-2019-7260 json | Linear eMerge E3-Series devices have Cleartext Credentials in a Database. | 9.8 - CRITICAL | 2019-07-02 | 2020-08-24 |
| CVE-2019-7259 json | Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure. | 8.8 - HIGH | 2019-07-02 | 2022-10-14 |
| CVE-2019-7258 json | Linear eMerge E3-Series devices allow Privilege Escalation. | 8.8 - HIGH | 2019-07-02 | 2022-10-14 |
| CVE-2019-7257 json | Linear eMerge E3-Series devices allow Unrestricted File Upload. | 10 - CRITICAL | 2019-07-02 | 2022-10-14 |
| CVE-2019-7256 json | Linear eMerge E3-Series devices allow Command Injections. | 10 - CRITICAL | 2019-07-02 | 2024-03-26 |
| CVE-2019-7255 json | Linear eMerge E3-Series devices allow XSS. | 6.1 - MEDIUM | 2019-07-02 | 2022-10-14 |