PT-2024-39634 · Linear · Linear Emerge E3-Series
Published
2024-10-02
·
Updated
2024-11-23
·
CVE-2024-9441
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linear eMerge e3-Series versions 1.00-07
Description
The Linear eMerge e3-Series is vulnerable to an OS command injection issue. A remote and unauthenticated attacker can execute arbitrary OS commands via the
login id parameter when invoking the forgot password functionality over HTTP. The vulnerability is actively exploited in the wild.Recommendations
For Linear eMerge e3-Series versions 1.00-07, as a temporary workaround, consider disabling the
forgot password functionality until a patch is available. Restrict access to the login id parameter in the affected HTTP endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linear Emerge E3-Series