Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x349-pfpf-whrf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.6

Описание

NCR SelfServ ATMs running APTRA XFS 05.01.00 or earlier do not authenticate or protect the integrity of USB HID communications between the currency dispenser and the host computer, permitting an attacker with physical access to internal ATM components the ability to inject a malicious payload and execute arbitrary code with SYSTEM privileges on the host computer by causing a buffer overflow on the host.

NCR SelfServ ATMs running APTRA XFS 05.01.00 or earlier do not authenticate or protect the integrity of USB HID communications between the currency dispenser and the host computer, permitting an attacker with physical access to internal ATM components the ability to inject a malicious payload and execute arbitrary code with SYSTEM privileges on the host computer by causing a buffer overflow on the host.

EPSS

Процентиль: 45%
0.00221
Низкий

7.6 High

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 7.6
nvd
больше 5 лет назад

NCR SelfServ ATMs running APTRA XFS 05.01.00 or earlier do not authenticate or protect the integrity of USB HID communications between the currency dispenser and the host computer, permitting an attacker with physical access to internal ATM components the ability to inject a malicious payload and execute arbitrary code with SYSTEM privileges on the host computer by causing a buffer overflow on the host.

EPSS

Процентиль: 45%
0.00221
Низкий

7.6 High

CVSS3

Дефекты

CWE-120