标题:NCR Command Center Agent 操作系统命令注入漏洞
(CVE-2021-3122) Description:NCR Aloha Essentials是美国NCR公司的移动POS功能硬件。提供了端到端的餐厅管理平台 NCR Command Center Agent 16.3 中的 CMCAgent存在安全漏洞,该漏洞源于允许提交runCommand参数(在XML文档发送到端口8089),未经身份验证攻击者可利用该漏洞执行任意命令系统。
介绍
# CVE-2021-3122-Details
Blog Post on how we found a CVE in AlohaPOS.
https://www.sentinelone.com/blog/cve-2021-3122-how-we-caught-a-threat-actor-exploiting-ncr-pos-zero-day/