PT-2024-13398 · Ncr · Ncr Terminal Handler

30T4

+1

·

Published

2024-02-08

·

Updated

2024-03-02

·

CVE-2023-47020

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NCR Terminal Handler version 1.5.1
Description The issue involves Multiple Cross-Site Request Forgery (CSRF) chaining, allowing an attacker to escalate privileges through a crafted request. This request involves user account creation and adding the user to an administrator group. The exploitation is facilitated by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.
Recommendations For NCR Terminal Handler version 1.5.1, consider disabling the WSDL function that lacks security controls until a patch is available to prevent the acceptance of custom content types and mitigate the risk of CSRF chaining. Restrict access to user account creation and administrator group management to minimize the risk of exploitation.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-47020

Affected Products

Ncr Terminal Handler