CVE-2023-47297 Details
Description
A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system security auditing configurations.
A vulnerability in NCR Terminal Handler version 1.5.1 allows attackers to manipulate application roles and configurations, leading to the execution of arbitrary commands. This includes the ability to edit system security auditing settings. The vulnerability arises from improper handling of role management endpoints, which can be exploited to alter role statuses and descriptions, particularly those related to auditing logs. Such manipulations can disrupt application functionality by, for example, deactivating critical roles or deleting roles entirely, causing the application to malfunction.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://drive.google.com/file/d/1YzoJ2QuI9LEEpF8r5ZiCdTQtR9hfsXl7/view?usp=sharing | [email protected] | Permissions Required |
| https://github.com/pwahba/cve-research/blob/main/CVE-2023-47297/CVE-2023-47297.md | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| ncr terminal handler | 1.5.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 26, 2025 | Initial Analysis | [email protected] |
| Jun 24, 2025 | CVE Modified | CISA-ADP |
| Jun 23, 2025 | New CVE Received | [email protected] |