Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Vincenzo Bonforte

#18925of 53,633
14.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2023-18255
6.0
2023-05-04
Unknown · Mpos Tui Trustlet · CVE-2023-21500
**Name of the Vulnerable Software and Affected Versions** mPOS TUI trustlet versions prior to SMR May-2023 Release 1 **Description** A double free validation issue in the setPinPadImages function of the mPOS TUI trustlet allows local attackers to access the trustlet memory. **Recommendations** For versions prior to SMR May-2023 Release 1, update to SMR May-2023 Release 1 or later to resolve the issue.
PT-2023-18256
8.2
2023-05-04
Fiserv · Mpos · CVE-2023-21501
**Name of the Vulnerable Software and Affected Versions** mPOS fiserve trustlet versions prior to SMR May-2023 Release 1 **Description** The issue is related to improper input validation, allowing local attackers to execute arbitrary code. This can be exploited by attackers to gain unauthorized access and control. **Recommendations** For versions prior to SMR May-2023 Release 1, update to SMR May-2023 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting local access to the mPOS fiserve trustlet to minimize the risk of exploitation.