Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-3122

Опубликовано: 07 фев. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Высокий

Описание

CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as exploited in the wild in 2020 and/or 2021. NOTE: the vendor's position is that exploitation occurs only on devices with a certain "misconfiguration."

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ncr:command_center_agent:16.3:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.87096
Высокий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

github
больше 3 лет назад

CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as exploited in the wild in 2020 and/or 2021. NOTE: the vendor's position is that exploitation occurs only on devices with a certain "misconfiguration."

EPSS

Процентиль: 99%
0.87096
Высокий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-78