CVE-2023-47022: Medium severity NCR Terminal Handler vulnerability
Published Feb 6, 2024
·Updated
Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV injection.
Affected Software
1 affected component
NCR Terminal Handler=1.5.1
Event History
Feb 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-47022?
CVE-2023-47022 is considered a high severity vulnerability due to the potential for unauthorized access to modify audit logs.
2
How do I fix CVE-2023-47022?
To fix CVE-2023-47022, upgrade NCR Terminal Handler to the latest version that addresses this vulnerability.
3
What impact does CVE-2023-47022 have on affected systems?
CVE-2023-47022 allows unprivileged users to edit audit logs, which can lead to data manipulation and potential CSV injection.
4
Who is affected by CVE-2023-47022?
All users of NCR Terminal Handler version 1.5.1 are affected by CVE-2023-47022.
5
What can be done to mitigate CVE-2023-47022 before a fix is available?
To mitigate CVE-2023-47022, implement strict access controls and monitor audit logs for unauthorized changes.