CVE-2023-47298

MEDIUM

NCR Terminal Handler 1.5.1 - Authenticated Exposure of Sensitive Information via SOAP API Endpoint

Title source: llm
STIX 2.1

Description

An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses.

Scores

CVSS v3 4.3
EPSS 0.0023
EPSS Percentile 14.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
ncr/terminal_handler 1.5.1
Published Jun 23, 2025
Tracked Since Feb 18, 2026