CVE Feed

    Dashboard / CVE / CVE-2021-3122

    CVE-2021-3122

    CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as exploited in the wild in 2020 and/or 2021. NOTE: the vendor's position is that exploitation occurs only on devices with a certain "misconfiguration."

    Published:Feb 7, 2021
    Last Modified:Nov 21, 2024
    EPS:Feb 7, 2021
    EPSS Score:0.12948
    CVSS Score:9.8

    Affected Products

    Vendor
    Ncr
    Product
    Command Center Agent

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High