PT-2021-19204 · Ncr · Ncr Command Center Agent
Kyle Pagelow
·
Published
2021-02-07
·
Updated
2025-10-29
·
CVE-2021-3122
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NCR Command Center Agent version 16.3
Description
The CMCAgent component in NCR Command Center Agent version 16.3, used on Aloha POS/BOH servers, allows for the submission of a
runCommand parameter within an XML document sent to port 8089. This enables remote, unauthenticated execution of arbitrary commands as SYSTEM. This issue was exploited in real-world attacks during 2020 and 2021, and has been linked to credit card theft incidents. The vendor states that exploitation requires a specific "misconfiguration." The vulnerable component accepts commands via the ''/'' API endpoint on port 8089. The runCommand parameter is submitted within an XML document.Recommendations
Versions prior to 16.3 are potentially affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ncr Command Center Agent