S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-31499 Scanner

Detects 'Command Injection' vulnerability in Nortek Linear eMerge E3-Series affects v. before 0.32-08f.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-31499
9.8
CVSS

Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The Nortek Linear eMerge E3-Series software is an advanced access control system used to secure commercial and residential buildings. This software provides users with cutting-edge technology to help manage access to their premises, which can include a variety of features, such as card readers, proximity sensors, and biometric scanners. Whether it's a small retail shop or a large manufacturing facility, the Nortek Linear eMerge E3-Series software is designed to provide robust and reliable security measures for all types of businesses.

The CVE-2022-31499 vulnerability is a critical security flaw that has been detected in the Nortek Linear eMerge E3-Series devices before 0.32-08f. This vulnerability enables an unauthenticated attacker to inject OS commands via ReaderNo. This issue exists because of an incomplete fix for CVE-2019-7256. This vulnerability puts all types of businesses and organizations at risk of security breaches and unauthorized access.

The exploitation of CVE-2022-31499 vulnerability can lead to significant damage to the security of the system. Attackers can execute arbitrary code on the affected system, leading to disruption of critical system functionality, loss of data, and unauthorized access to confidential information. This can ultimately lead to severe financial and reputational damage for businesses. Therefore, it is essential to take appropriate precautions to prevent the exploitation of this vulnerability.

In conclusion, it's essential to keep your digital assets secure to protect your business from unnecessary losses. s4e.io provides pro features that help individuals and businesses learn about their digital asset vulnerabilities quickly and easily. Take advantage of these pro features and stay informed about the latest security threats and vulnerabilities to safeguard your information. Remember, security is not only important but also necessary for every digital asset.

 

REFERENCES

Solution Advice

Here are some precautions that businesses can take to protect against this vulnerability:

  • Update the Nortek Linear eMerge E3-Series devices to the latest version, which includes a complete fix for CVE-2019-7256.
  • Regularly monitor the system for any suspicious activity.
  • Ensure that the system is only accessible by authorized personnel.
  • Implement a robust and updated antivirus solution.
  • Conduct regular security assessments to identify and address any potential vulnerabilities and security threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-31499 scanner - Command Injection vulnerability in Nortek Linear eMerge E3-Series | S4E