HomeSecurityVulnerability in Linear eMerge E3 devices allows DDoS attacks

Vulnerability in Linear eMerge E3 devices allows DDoS attacks

According to security company SonicWall , hackers are searching the Internet for vulnerable systems access control in smart building doors, with the aim of breaching them and carrying out DDoS attacks .DDoS

The attackers are targeting the Linear eMerge E3, a product of Nortek Security & Control (NSC), a global leader in smart devices.

Linear eMerge E3 devices belong to the category of access . They are usually used in corporate offices, factories or industrial parks. Essentially they control which doors and rooms/areas employees and visitors/customers can access based on credentials (access codes) or smart cards .

About a year ago, researchers at Applied Risk, which specializes in industrial services security, uncovered ten vulnerabilities affecting NSC's Linear eMerge E3 devices.

According to the researchers, the company had been informed of the vulnerabilities, and despite the fact that six of the ten were extremely serious, NSC did not release patches.

A few months later, Applied Risk published proof-of-concept exploit code.

Exploitation of the CVE-2019-7256 vulnerability to carry out DDoS attacks

Now, SonicWall researchers have published a report stating that some hackers are scanning the internet to identify and compromise vulnerable NSC Linear eMerge E3 devices, exploiting one of those ten vulnerabilities.

The vulnerability they are exploiting is CVE-2019-7256. It is a “command injection” vulnerability and is one of the most serious that has been found on devices. It can be used remotely even by hackers with minimal technical knowledge to carry out DDoS and other attacks.

According to SonicWall, attackers are able to perform arbitrary command execution with administrator privileges. “An unauthenticated, remote attacker could exploit the vulnerability to execute commands via a crafted HTTP request,” the researchers.

Hackers use CVE-2019-7256 to take control of devices, install malware , and then carry out DDoS attacks on other targets.

The first of these attacks began on January 9th and was detected by researchers at Bad Packets. According to the company, there have been several other attacks since then.

“Attackers appear to be continuously targeting these devices as we see tens of thousands of hits every day,” SonicWall said. The attacks are taking place in 100 countries, but the main target is the United States.

So far, only 2,375 vulnerable devices have been identified. That number is very small compared to the millions of home routers and securitythat are also available online. However, attackers continue to scan.

Vulnerability in Linear eMerge E3 devices allows DDoS attacks

devices are used as entry points into systems

Vulnerable smart access control systems can be used as entry points into an organization's internal networks.

In August 2019, Microsoft identified a Russian hacking group that was using smart Internet of Things (IoT) devices as entry points to carry out DDoS and other attacks on corporate networks.

System administrators managing networks with NSC Linear eMerge E3 devices installed should disconnect the systems from the internet or at least restrict access to these devices using a firewall or VPN.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS