CVE-2017-17668
Summary
| CVE | CVE-2017-17668 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-20 14:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Memory write mechanism in NCR S1 Dispenser controller before firmware version 0x0156 allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions with known vulnerabilities. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ncr | S1 Dispenser Controller | - | All | All | All |
| Hardware | Ncr | S1 Dispenser Controller | - | All | All | All |
| Operating System | Ncr | S1 Dispenser Controller Firmware | All | All | All | All |
| Operating System | Ncr | S1 Dispenser Controller Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Page not found | NCR | CONFIRM | www.ncr.com | Broken Link, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.