CVE-2018-5717: High severity NCR S2 Dispenser Controller Firmware vulnerability
Published Mar 20, 2018
·Updated
Memory write mechanism in NCR S2 Dispenser controller before firmware version 0x0108 allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions with known vulnerabilities.
Affected Software
4 affected components
NCR S2 Dispenser Controller Firmware<0x0108
NCR S2 Dispenser controller
All of the following
NCR S2 Dispenser Controller Firmware<0x0108
NCR S2 Dispenser controller
Event History
Mar 20, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5717?
CVE-2018-5717 is classified as a critical vulnerability due to its potential impact on device integrity.
2
How do I fix CVE-2018-5717?
To fix CVE-2018-5717, upgrade the NCR S2 Dispenser controller firmware to version 0x0108 or higher.
3
Who is affected by CVE-2018-5717?
CVE-2018-5717 affects NCR S2 Dispenser controllers running firmware versions prior to 0x0108.
4
What are the risks associated with CVE-2018-5717?
The risks include unauthorized firmware upgrades or downgrades, potentially exposing the device to known vulnerabilities.
5
Is authentication required to exploit CVE-2018-5717?
No, CVE-2018-5717 can be exploited by unauthenticated users.