CVE-2018-5717
Summary
| CVE | CVE-2018-5717 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-20 14:29:00 UTC |
| Updated | 2018-04-20 14:57:00 UTC |
| Description | Memory write mechanism in NCR S2 Dispenser controller before firmware version 0x0108 allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions with known vulnerabilities. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ncr | S2 Dispenser Controller | - | All | All | All |
| Hardware | Ncr | S2 Dispenser Controller | - | All | All | All |
| Operating System | Ncr | S2 Dispenser Controller Firmware | All | All | All | All |
| Operating System | Ncr | S2 Dispenser Controller Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Page not found | NCR | CONFIRM | www.ncr.com | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.