PT-2025-26610 · Ncr · Ncr Terminal Handler

CVE-2023-47294

·

Published

2025-06-23

·

Updated

2025-06-28

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: NCR Terminal Handler version 1.5.1
Description: The issue allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete user accounts via a crafted session cookie.
Recommendations: For NCR Terminal Handler version 1.5.1, consider restricting access to user account management features until a patch is available. As a temporary workaround, monitor user account activity closely to detect and respond to potential unauthorized modifications.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-47294

Affected Products

Ncr Terminal Handler