PT-2024-13398 · Ncr · Ncr Terminal Handler
30T4
+1
·
Published
2024-02-08
·
Updated
2024-03-02
·
CVE-2023-47020
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NCR Terminal Handler version 1.5.1
Description
The issue involves Multiple Cross-Site Request Forgery (CSRF) chaining, allowing an attacker to escalate privileges through a crafted request. This request involves user account creation and adding the user to an administrator group. The exploitation is facilitated by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.
Recommendations
For NCR Terminal Handler version 1.5.1, consider disabling the WSDL function that lacks security controls until a patch is available to prevent the acceptance of custom content types and mitigate the risk of CSRF chaining. Restrict access to user account creation and administrator group management to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ncr Terminal Handler