Home/Product/ncr terminal handler
Product

ncr terminal handler

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-47030
all versions
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a
9.8CRITICAL
CVE-2023-47029
all versions
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a
9.8CRITICAL
CVE-2023-47031
all versions
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRo
9.8CRITICAL
CVE-2023-47295
all versions
A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafte
9.8CRITICAL
CVE-2023-47294
all versions
An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and d
8.1HIGH
CVE-2023-47032
all versions
Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted script to
9.8CRITICAL
CVE-2023-47298
all versions
An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obta
4.3MEDIUM
CVE-2023-47297
all versions
A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including edi
9.8CRITICAL
CVE-2023-47020
all versions
Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attack
8.8HIGH
CVE-2023-47022
all versions
Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user a
6.5MEDIUM
CVE-2023-47024
all versions
Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by explo
8.8HIGH
threatengine.sh