CVE-2023-47298

MEDIUM

NCR Terminal Handler - Information Disclosure

Title source: rule
STIX 2.1

Description

An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses.

Scores

CVSS v3 4.3
EPSS 0.0019
EPSS Percentile 40.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
ncr/terminal_handler 1.5.1
Published Jun 23, 2025
Tracked Since Feb 18, 2026