Executive brief
Nice Linear eMerge E3-Series access controllers contain an OS command injection vulnerability in multiple PHP scripts, including card_scan.php and card_scan_decoder.php. This flaw allows unauthenticated remote attackers to execute arbitrary commands on the underlying operating system with elevated privileges.
Affected products
- Nice Linear eMerge E3-Series 1.00-06
Timeline
- 2019-11-12: disclosed: Initial public disclosure of exploit via Packet Storm
- 2024-03-25: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
- 2024-03-25: advisory: NVD publication date
- 2024-03-25: exploited: Confirmed exploited in the wild per CISA KEV entry