CVE-2018-17770 describes a buffer overflow vulnerability in Ingenico Telium 2 POS terminals, specifically exploitable via the RemotePutFile command of the NTPT3 protocol. This vulnerability carries a CVSS score of 6.6 (Medium), indicating that an attacker with physical or local access could achieve high confidentiality, integrity, and availability impacts. While the vulnerability is fixed in Telium 2 SDK v9.32.03 patch N, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.32.03CPE matchmatch criteria | cpe:2.3:o:ingenico:telium_2_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.