Vulnerabilities (CVE)

Filtered by vendor Nortekcontrol Subscribe
Filtered by product Emerge E3 Firmware
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-31798 1 Nortekcontrol 2 Emerge E3, Emerge E3 Firmware 2023-08-08 N/A 6.1 MEDIUM
Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation (via PHPSESSID) when they are chained together. This would allow an attacker to take over an admin account or a user account.