You are here

Nortek Linear eMerge 50P/5000P (ICSA-20-184-01)

Nortek Linear eMerge 50P/5000P (ICSA-20-184-01)

Created: Tuesday, July 7, 2020 - 11:59
Categories:
Cybersecurity

CISA has published an advisory on path traversal, command injection, unrestricted upload of file with dangerous type, cross-site request forgery, and improper authentication vulnerabilities in Nortek Linear eMerge 50P/5000P. Versions 4.6.07 (revision 79330) and prior are affected. Successful exploitation of these vulnerabilities could allow a remote attacker to gain full system access. Nortek has released v32-09a to address the vulnerabilities. CISA also recommends a series of measures to mitigate the vulnerabilities. Access the advisory at CISA.