CVE-2023-3655 is a high-severity vulnerability affecting cashIT! point-of-sale (PoS) devices up to version 2023.02.37, specifically those from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH". This flaw, rated 7.5 CVSS, allows an unauthenticated attacker to remotely leak sensitive database information, including system settings and user accounts, via an exposed HTTP endpoint. While no public exploit intelligence or active exploitation has been observed, the vulnerability presents a significant risk due to its low attack complexity and high impact on confidentiality. Community discussion and media coverage for this CVE are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 03.a06rks_2023.02.37CPE matchmatch criteria | cpe:2.3:a:cashit:cashit\!:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.