CVE-2019-7256 · netVigilance record NV24-0037
Nice Linear eMerge E3-Series OS Command Injection
past due
What to do
Contact the vendor for guidance on remediating firmware, per their advisory.
CISA deadline 2024-04-15 · passed 2 years 4 months ago · applies to US federal civilian agencies; used elsewhere as a reference SLA
What happened
Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution.
Who is affected
Nice Linear eMerge E3-Series. Affected version ranges are listed in the vendor advisory and the NVD entry linked under Sources.
Weakness class: CWE-78.
Timeline
- Added to CISA KEVExploitation in the wild confirmed by CISA
- CISA remediation deadlinepassed 2 years 4 months ago
Sources
- NVD entry for CVE-2019-7256 nvd.nist.gov/vuln/detail/CVE-2019-7256
- CISA Known Exploited Vulnerabilities catalog www.cisa.gov/known-exploited-vulnerabilities-catalog
- linear-solutions.com linear-solutions.com/wp-content/uploads/E3-Bulletin-06-27-2023.pdf
- cisa.gov www.cisa.gov/news-events/ics-advisories/icsa-24-065-01
- nvd.nist.gov nvd.nist.gov/vuln/detail/CVE-2019-7256