Записи nortekcontrol
25 опубликованных записей вендора nortekcontrol.
Профиль для исследователя
- Попали в KEV
- 1 · 4 %
- С эксплойтом
- 1 · 4 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 1728 дн.
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-798 Use of Hard-coded Credentials3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-522 Insufficiently Protected Credentials2
- CWE-352 Cross-Site Request Forgery (CSRF)2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
25 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
98Срочно | CVE-2019-7256Готовый эксплойт | Linear eMerge E3-Series devices allow Command Injections.nortekcontrol · linear emerge essential firmware · CWE-78 | Критическая9,8 | KEV | 97,1 % | 2 июл. 2019 г. |
61На этой неделе | CVE-2019-7257Proof of concept | Linear eMerge E3-Series devices allow Unrestricted File Upload.nortekcontrol · linear emerge essential firmware · CWE-434 | Критическая10,0 | — | 70,0 % | 2 июл. 2019 г. |
58В плане | CVE-2022-31499Proof of concept | Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo.nortekcontrol · emerge e3 firmware · CWE-78 | Критическая9,8 | — | 64,6 % | 25 авг. 2022 г. |
55В плане | CVE-2019-7254Proof of concept | Linear eMerge E3-Series devices allow File Inclusion.nortekcontrol · linear emerge essential firmware · CWE-22 | Высокая7,5 | — | 82,3 % | 2 июл. 2019 г. |
55В плане | CVE-2024-9441Proof of concept | Linear eMerge e3-Series Forgot Password Command Injectionlinear · emerge e3-series · CWE-78 | Критическая9,8 | — | 53,5 % | 2 окт. 2024 г. |
51В плане | CVE-2019-7269Proof of concept | Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.nortekcontrol · linear emerge 50p firmware · CWE-78 | Критическая9,8 | — | 40,0 % | 2 июл. 2019 г. |
46В плане | CVE-2019-7265Proof of concept | Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).nortekcontrol · linear emerge essential firmware · CWE-798 | Критическая9,8 | — | 23,1 % | 2 июл. 2019 г. |
45В плане | CVE-2019-7267Эксплойта нет | Linear eMerge 50P/5000P devices allow Cookie Path Traversal.nortekcontrol · linear emerge 50p firmware · CWE-22 | Критическая9,8 | — | 21,5 % | 2 июл. 2019 г. |
42В плане | CVE-2019-7268Эксплойта нет | Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.nortekcontrol · linear emerge 50p firmware · CWE-434 | Критическая10,0 | — | 6,5 % | 2 июл. 2019 г. |
41В плане | CVE-2019-7255Proof of concept | Linear eMerge E3-Series devices allow XSS.nortekcontrol · linear emerge essential firmware · CWE-79 | Средняя6,1 | — | 55,8 % | 2 июл. 2019 г. |
41В плане | CVE-2019-7258Эксплойта нет | Linear eMerge E3-Series devices allow Privilege Escalation.nortekcontrol · linear emerge essential firmware · CWE-863 | Высокая8,8 | — | 19,6 % | 2 июл. 2019 г. |
41В плане | CVE-2019-7260Эксплойта нет | Linear eMerge E3-Series devices have Cleartext Credentials in a Database.nortekcontrol · linear emerge essential firmware · CWE-522 | Критическая9,8 | — | 6,6 % | 2 июл. 2019 г. |
41В плане | CVE-2019-7261Эксплойта нет | Linear eMerge E3-Series devices have Hard-coded Credentials.nortekcontrol · linear emerge essential firmware · CWE-798 | Критическая9,8 | — | 5,5 % | 2 июл. 2019 г. |
40В плане | CVE-2019-7262Proof of concept | Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).nortekcontrol · linear emerge essential firmware · CWE-352 | Высокая8,8 | — | 16,3 % | 2 июл. 2019 г. |
40В плане | CVE-2019-7252Эксплойта нет | Linear eMerge E3-Series devices have Default Credentials.nortekcontrol · linear emerge essential firmware · CWE-1188 | Критическая9,8 | — | 4,9 % | 2 июл. 2019 г. |
40В плане | CVE-2019-7266Эксплойта нет | Linear eMerge 50P/5000P devices allow Authentication Bypass.nortekcontrol · linear emerge 50p firmware · CWE-565 | Критическая9,8 | — | 4,6 % | 2 июл. 2019 г. |
40В плане | CVE-2018-5439Эксплойта нет | A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior.nortekcontrol · emerge e3 firmware · CWE-77 | Критическая9,8 | — | 4,2 % | 19 февр. 2018 г. |
40В плане | CVE-2019-7271Эксплойта нет | Nortek Linear eMerge 50P/5000P devices have Default Credentials.nortekcontrol · linear emerge 50p firmware · CWE-522 | Критическая9,8 | — | 3,6 % | 1 июл. 2019 г. |
40В плане | CVE-2019-7253Эксплойта нет | Linear eMerge E3-Series devices allow Directory Traversal.nortekcontrol · linear emerge essential firmware · CWE-22 | Критическая9,8 | — | 3,0 % | 2 июл. 2019 г. |
40В плане | CVE-2019-7264Эксплойта нет | Linear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform.nortekcontrol · linear emerge essential firmware · CWE-787 | Критическая9,8 | — | 2,2 % | 2 июл. 2019 г. |
40В плане | CVE-2019-7263Эксплойта нет | Linear eMerge E3-Series devices have a Version Control Failure.nortekcontrol · linear emerge essential firmware · CWE-18 | Критическая9,8 | — | 1,8 % | 2 июл. 2019 г. |
39Наблюдать | CVE-2019-7259Эксплойта нет | Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.nortekcontrol · linear emerge essential firmware · CWE-200 | Высокая8,8 | — | 13,2 % | 2 июл. 2019 г. |
35Наблюдать | CVE-2019-7270Эксплойта нет | Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).nortekcontrol · linear emerge 50p firmware · CWE-352 | Высокая8,8 | — | 1,1 % | 2 июл. 2019 г. |
34Наблюдать | CVE-2022-31269Proof of concept | Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doonortekcontrol · emerge e3 firmware · CWE-798 | Высокая8,2 | — | 7,0 % | 25 авг. 2022 г. |
27Наблюдать | CVE-2022-31798Proof of concept | Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) whenortekcontrol · emerge e3 firmware · CWE-384 | Средняя6,1 | — | 8,5 % | 25 авг. 2022 г. |
- CVE-2019-725698Срочно
Linear eMerge E3-Series devices allow Command Injections.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2019-725761На этой неделе
Linear eMerge E3-Series devices allow Unrestricted File Upload.
КритическаяCVSS 10,0Proof of conceptEPSS 70 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2022-3149958В плане
Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo.
КритическаяCVSS 9,8Proof of conceptEPSS 65 %nortekcontrol · emerge e3 firmware25 авг. 2022 г.
- CVE-2019-725455В плане
Linear eMerge E3-Series devices allow File Inclusion.
ВысокаяCVSS 7,5Proof of conceptEPSS 82 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2024-944155В плане
Linear eMerge e3-Series Forgot Password Command Injection
КритическаяCVSS 9,8Proof of conceptEPSS 53 %linear · emerge e3-series2 окт. 2024 г.
- CVE-2019-726951В плане
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
КритическаяCVSS 9,8Proof of conceptEPSS 40 %nortekcontrol · linear emerge 50p firmware2 июл. 2019 г.
- CVE-2019-726546В плане
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
КритическаяCVSS 9,8Proof of conceptEPSS 23 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2019-726745В плане
Linear eMerge 50P/5000P devices allow Cookie Path Traversal.
КритическаяCVSS 9,8Эксплойта нетEPSS 21 %nortekcontrol · linear emerge 50p firmware2 июл. 2019 г.
- CVE-2019-726842В плане
Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %nortekcontrol · linear emerge 50p firmware2 июл. 2019 г.
- CVE-2019-725541В плане
Linear eMerge E3-Series devices allow XSS.
СредняяCVSS 6,1Proof of conceptEPSS 56 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2019-725841В плане
Linear eMerge E3-Series devices allow Privilege Escalation.
ВысокаяCVSS 8,8Эксплойта нетEPSS 20 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2019-726041В плане
Linear eMerge E3-Series devices have Cleartext Credentials in a Database.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2019-726141В плане
Linear eMerge E3-Series devices have Hard-coded Credentials.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2019-726240В плане
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
ВысокаяCVSS 8,8Proof of conceptEPSS 16 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2019-725240В плане
Linear eMerge E3-Series devices have Default Credentials.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2019-726640В плане
Linear eMerge 50P/5000P devices allow Authentication Bypass.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %nortekcontrol · linear emerge 50p firmware2 июл. 2019 г.
- CVE-2018-543940В плане
A Command Injection issue was discovered in Nortek Linear eMerge E3 series Versions V0.32-07e and prior.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %nortekcontrol · emerge e3 firmware19 февр. 2018 г.
- CVE-2019-727140В плане
Nortek Linear eMerge 50P/5000P devices have Default Credentials.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %nortekcontrol · linear emerge 50p firmware1 июл. 2019 г.
- CVE-2019-725340В плане
Linear eMerge E3-Series devices allow Directory Traversal.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2019-726440В плане
Linear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2019-726340В плане
Linear eMerge E3-Series devices have a Version Control Failure.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2019-725939Наблюдать
Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.
ВысокаяCVSS 8,8Эксплойта нетEPSS 13 %nortekcontrol · linear emerge essential firmware2 июл. 2019 г.
- CVE-2019-727035Наблюдать
Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nortekcontrol · linear emerge 50p firmware2 июл. 2019 г.
- CVE-2022-3126934Наблюдать
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doo
ВысокаяCVSS 8,2Proof of conceptEPSS 7 %nortekcontrol · emerge e3 firmware25 авг. 2022 г.
- CVE-2022-3179827Наблюдать
Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) whe
СредняяCVSS 6,1Proof of conceptEPSS 9 %nortekcontrol · emerge e3 firmware25 авг. 2022 г.