CVE-2024-9441 is a critical OS command injection vulnerability affecting Linear eMerge e3-Series access control systems up to version 1.00-07. A remote, unauthenticated attacker can exploit this flaw by manipulating the login_id parameter during a password reset request over HTTP, leading to arbitrary OS command execution. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction, allowing for complete compromise of confidentiality, integrity, and availability. While not yet listed in CISA KEV, its high EPSS score and significant community discussion indicate a strong potential for future exploitation, though no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linear | EMerge E3-Series | >= 0, <= 1.00-07CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.