PT-2024-13398 · Ncr · Ncr Terminal Handler

·

CVE-2023-47020

·

Published

2024-02-08

·

Updated

2024-03-02

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NCR Terminal Handler version 1.5.1
Description The issue involves Multiple Cross-Site Request Forgery (CSRF) chaining, allowing an attacker to escalate privileges through a crafted request. This request involves user account creation and adding the user to an administrator group. The exploitation is facilitated by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.
Recommendations For NCR Terminal Handler version 1.5.1, consider disabling the WSDL function that lacks security controls until a patch is available to prevent the acceptance of custom content types and mitigate the risk of CSRF chaining. Restrict access to user account creation and administrator group management to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-47020

Affected Products

Ncr Terminal Handler