Vulnerabilities > CVE-2018-5717 - Out-of-bounds Write vulnerability in NCR S2 Dispenser Controller Firmware

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
COMPLETE
Availability impact
NONE
network
low complexity
ncr
CWE-787

Summary

Memory write mechanism in NCR S2 Dispenser controller before firmware version 0x0108 allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions with known vulnerabilities.

Vulnerable Configurations

Part Description Count
OS
Ncr
1
Hardware
Ncr
1

Common Weakness Enumeration (CWE)