CVE-2023-47298
Last modified
CVE-2023-47298 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ncr | Terminal Handler | 1.5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-47298?
How severe is CVE-2023-47298?
How do I fix CVE-2023-47298?
Are you affected by CVE-2023-47298?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
