PT-2025-26603 · Ncr · Ncr Terminal Handler

Published

2025-06-23

·

Updated

2025-06-23

·

CVE-2023-47298

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: NCR Terminal Handler version 1.5.1
Description: An issue allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application, including their usernames, roles, security groups, and account statuses.
Recommendations: For NCR Terminal Handler version 1.5.1, consider restricting access to the SOAP API endpoint to minimize the risk of exploitation. As a temporary workaround, limit the privileges of low-level authenticated attackers to prevent them from querying sensitive user information.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-47298

Affected Products

Ncr Terminal Handler