Vulnerabilities > Nortekcontrol

DATE CVE VULNERABILITY TITLE RISK
2019-07-02 CVE-2019-7262 Cross-Site Request Forgery (CSRF) vulnerability in Nortekcontrol products
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
network
low complexity
nortekcontrol CWE-352
8.8
2019-07-02 CVE-2019-7261 Use of Hard-coded Credentials vulnerability in Nortekcontrol products
Linear eMerge E3-Series devices have Hard-coded Credentials.
network
low complexity
nortekcontrol CWE-798
critical
9.8
2019-07-02 CVE-2019-7260 Insufficiently Protected Credentials vulnerability in Nortekcontrol products
Linear eMerge E3-Series devices have Cleartext Credentials in a Database.
network
low complexity
nortekcontrol CWE-522
critical
9.8
2019-07-02 CVE-2019-7259 Information Exposure vulnerability in Nortekcontrol products
Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.
network
low complexity
nortekcontrol CWE-200
8.8
2019-07-02 CVE-2019-7270 Cross-Site Request Forgery (CSRF) vulnerability in Nortekcontrol products
Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).
network
low complexity
nortekcontrol CWE-352
8.8
2019-07-02 CVE-2019-7269 OS Command Injection vulnerability in Nortekcontrol products
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
network
low complexity
nortekcontrol CWE-78
critical
9.8
2019-07-02 CVE-2019-7268 Unrestricted Upload of File with Dangerous Type vulnerability in Nortekcontrol products
Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.
network
low complexity
nortekcontrol CWE-434
critical
10.0
2019-07-02 CVE-2019-7267 Path Traversal vulnerability in Nortekcontrol products
Linear eMerge 50P/5000P devices allow Cookie Path Traversal.
network
low complexity
nortekcontrol CWE-22
critical
9.8
2019-07-02 CVE-2019-7266 Reliance on Cookies without Validation and Integrity Checking vulnerability in Nortekcontrol products
Linear eMerge 50P/5000P devices allow Authentication Bypass.
network
low complexity
nortekcontrol CWE-565
critical
9.8
2019-07-02 CVE-2019-7265 Use of Hard-coded Credentials vulnerability in Nortekcontrol products
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
network
low complexity
nortekcontrol CWE-798
critical
9.8