Unpatched OS command injection in Nice Linear eMerge E3 controllers
- Company
- Nice North America
- CVE ID
- CVE-2024-9441
- Severity
- Critical
- CVSS
- 9.80
- Source URL
- nvd.nist.gov
- Vendor notified at
- 2025-04-24 00:00:00
The forgot-password login_id parameter in Linear eMerge E3-series access controllers (through 1.00-07) allows unauthenticated OS command injection. Public proof-of-concept exploits circulate; the vendor has advised network segmentation rather than shipping a patch.
Source: nvd.nist.gov