PT-2025-26603 · Ncr · Ncr Terminal Handler
Published
2025-06-23
·
Updated
2025-06-23
·
CVE-2023-47298
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
NCR Terminal Handler version 1.5.1
Description:
An issue allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application, including their usernames, roles, security groups, and account statuses.
Recommendations:
For NCR Terminal Handler version 1.5.1, consider restricting access to the SOAP API endpoint to minimize the risk of exploitation. As a temporary workaround, limit the privileges of low-level authenticated attackers to prevent them from querying sensitive user information.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ncr Terminal Handler