9.8
CVSSv3

CVE-2013-2571

Published: 28/01/2020 Updated: 06/02/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote malicious users to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hcomm xpient iris

Exploits

Core Security - Corelabs Advisory corelabscoresecuritycom/ Xpient Cash Drawer Operation Vulnerability 1 *Advisory Information* Title: Xpient Cash Drawer Operation Vulnerability Advisory ID: CORE-2013-0517 Advisory URL: wwwcoresecuritycom/advisories/xpient-cash-drawer-operation-vulnerability Date published: 2013-06-05 Date of ...
Core Security Technologies Advisory - A security vulnerability was found in Xpient POS systems running an instance of Iris 38 software The POS cash drawer could be remotely triggered to open if a malicious agent has access to the POS network and is allowed to send a crafted message to the POS terminal hosting the cash drawer The malicious agent ...