NCR maintains a portfolio of financial and retail transaction systems, including ATM platforms, point-of-sale terminals, and cash-handling infrastructure that operate in high-value, often network-connected environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes across products such as APTRA XFS, SelfServ ATM, and Terminal Handler, reflecting the security-sensitive role these systems play in financial infrastructure. The exposure recurs through access-control weaknesses, code-injection flaws, and authentication bypasses that are characteristic of systems requiring strict boundary enforcement between operator, customer, and administrative functions. Defenders should prioritize inventory and patching of deployed ATM and terminal systems, particularly those exposed to untrusted networks or operator interaction. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ncr over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3122CRITICAL CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remo | Feb 7, 2021 | 9.8 | 89 | NO | YES |
CVE-2023-48978CRITICAL An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL component. | Jun 23, 2025 | 9.8 | 30 | NO | NO |
CVE-2023-47030CRITICAL An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a GET request to a UserService SOAP API endpoint to | Jun 23, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-47031CRITICAL An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOr | Jun 23, 2025 | 9.8 | 28 | NO | NO |
CVE-2023-47295CRITICAL A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload into any text field that accepts strings | Jun 23, 2025 | 9.8 | 26 | NO | NO |
CVE-2023-47032CRITICAL Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the UserService SOAP API function. | Jun 23, 2025 | 9.8 | 26 | NO | NO |
CVE-2023-47297CRITICAL A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system security auditing configurations. | Jun 23, 2025 | 9.8 | 26 | NO | NO |
CVE-2023-47029CRITICAL An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted POST request to the UserService component | Jun 23, 2025 | 9.8 | 24 | NO | NO |
CVE-2020-9063HIGH NCR SelfServ ATMs running APTRA XFS 05.01.00 or earlier do not authenticate or protect the integrity of USB HID communications between the currency dispenser and the host computer, | Aug 21, 2020 | 7.6 | 24 | NO | NO |
CVE-2018-5717HIGH Memory write mechanism in NCR S2 Dispenser controller before firmware version 0x0108 allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to | Mar 20, 2018 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ncr.
Media articles that mention a CVE ID that affects a product developed by Ncr — matched by CVE ID, not by vendor name.