Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Jul 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ncr
Ncr terminal Handler |
|
| CPEs | cpe:2.3:a:ncr:terminal_handler:1.5.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Ncr
Ncr terminal Handler |
Thu, 26 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Mon, 23 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete user accounts via a crafted session cookie. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-06-26T15:11:39.439Z
Reserved: 2023-11-06T00:00:00.000Z
Link: CVE-2023-47294
Updated: 2025-06-26T15:11:33.428Z
Status : Analyzed
Published: 2025-06-23T16:15:24.493
Modified: 2025-07-02T19:10:16.237
Link: CVE-2023-47294
No data.
OpenCVE Enrichment
Updated: 2025-06-27T09:26:49Z