Back to search
CVE-2021-3122
Published: Feb 7, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as exploited in the wild in 2020 and/or 2021. NOTE: the vendor's position is that exploitation occurs only on devices with a certain "misconfiguration."
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://rdf2.alohaenterprise.com/client/CMCInst.zip
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now