Junglewise Threat Intelligence

CVE-2019-7256: Nice Linear eMerge E3-Series OS Command Injection Vulnerability

CVE-2019-7256 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-03-25

Executive brief

Nice Linear eMerge E3-Series access controllers contain an OS command injection vulnerability in multiple PHP scripts, including card_scan.php and card_scan_decoder.php. This flaw allows unauthenticated remote attackers to execute arbitrary commands on the underlying operating system with elevated privileges.

Affected products

  • Nice Linear eMerge E3-Series 1.00-06

Timeline

  • 2019-11-12: disclosed: Initial public disclosure of exploit via Packet Storm
  • 2024-03-25: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
  • 2024-03-25: advisory: NVD publication date
  • 2024-03-25: exploited: Confirmed exploited in the wild per CISA KEV entry