PT-2025-26604 · Ncr · Ncr Itm Web Terminal

Published

2025-06-23

·

Updated

2025-07-09

·

CVE-2023-48978

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: NCR ITM Web terminal versions 4.4.0 through 4.4.4
Description: The issue allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL component.
Recommendations: For versions 4.4.0 through 4.4.4, consider restricting access to the IP camera URL component until a patch is available. As a temporary workaround, avoid using the IP camera URL component in NCR ITM Web terminal until the issue is resolved.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-48978

Affected Products

Ncr Itm Web Terminal