S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-31798 Scanner

CVE-2022-31798 scanner - Cross-Site Scripting (XSS) vulnerability in Nortek Linear eMerge E3-Series

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-31798
6.1
CVSS

Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Nortek Linear eMerge E3-Series is a security access control system that is widely used for its reliability and efficiency. This product is designed to provide comprehensive security solutions for various premises, including corporate offices, warehouses, hospitals, schools, and other public institutions. The Nortek Linear eMerge E3-Series is known for its ability to support multiple cards and credentials, making it one of the most desirable access control systems on the market.

Recently, a security vulnerability, CVE-2022-31798, has been detected in the Nortek Linear eMerge E3-Series access control system. This vulnerability affects the system's /card_scan.php?CardFormatNo= endpoint and allows an attacker to exploit XSS (Cross-Site Scripting) with session fixation using the PHPSESSID. When these devices are chained together, this loophole in security can enable an attacker to take over an admin account or user account.

Exploiting the CVE-2022-31798 vulnerability can lead to severe consequences. Since an attacker can easily take control of the admin account or a user account, they can access all the confidential data and system logs. This vulnerability can give an attacker remote command execution access, allowing them to execute system-level commands and create new user accounts. If an attacker exploits this vulnerability, they can even disable the entire security access control that can put the entire facility at risk.

In conclusion, security vulnerabilities can pose significant risks to both individuals and organizations that rely on access control systems. Thanks to the pro feature of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform provides timely security updates, effective notifications, and expert support, helping users protect their digital assets from security threats. Therefore, it is crucial to keep up with the security updates and best practices to mitigate potential threats and avoid security breaches.

 

REFERENCES

Solution Advice

To avoid the risk of exploitation of the CVE-2022-31798 vulnerability, anyone using the Nortek Linear eMerge E3-Series access control should implement the following precautions:

  • Always keep the device firmware up to date with the most recent security patches.
  • Set up network isolation and restricted access controls to limit the exposure of the device to untrusted networks and users.
  • Use strong authentication credentials and enable two-factor authentication for all access control system accounts.
  • Monitor system logs for suspicious activity and unusual behavior.
  • Secure the device physical access, including remote and local access to the device, limiting physical access to authorized personnel.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.