Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ncr

First CVE: Apr 18, 1996Active for: 30 yearsTotal CVEs: 21
45.1
VTI Score
High

NCR maintains a portfolio of financial and retail transaction systems, including ATM platforms, point-of-sale terminals, and cash-handling infrastructure that operate in high-value, often network-connected environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes across products such as APTRA XFS, SelfServ ATM, and Terminal Handler, reflecting the security-sensitive role these systems play in financial infrastructure. The exposure recurs through access-control weaknesses, code-injection flaws, and authentication bypasses that are characteristic of systems requiring strict boundary enforcement between operator, customer, and administrative functions. Defenders should prioritize inventory and patching of deployed ATM and terminal systems, particularly those exposed to untrusted networks or operator interaction. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ncr over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 1996
30 years ago
Most Recent CVE
Jun 23, 2025
396 days ago

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-3122CRITICAL
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remo
Feb 7, 20219.889NOYES
CVE-2023-48978CRITICAL
An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL component.
Jun 23, 20259.830NONO
CVE-2023-47030CRITICAL
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a GET request to a UserService SOAP API endpoint to
Jun 23, 20259.829NONO
CVE-2023-47031CRITICAL
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOr
Jun 23, 20259.828NONO
CVE-2023-47295CRITICAL
A CSV injection vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands via injecting a crafted payload into any text field that accepts strings
Jun 23, 20259.826NONO
CVE-2023-47032CRITICAL
Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the UserService SOAP API function.
Jun 23, 20259.826NONO
CVE-2023-47297CRITICAL
A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system security auditing configurations.
Jun 23, 20259.826NONO
CVE-2023-47029CRITICAL
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted POST request to the UserService component
Jun 23, 20259.824NONO
CVE-2020-9063HIGH
NCR SelfServ ATMs running APTRA XFS 05.01.00 or earlier do not authenticate or protect the integrity of USB HID communications between the currency dispenser and the host computer,
Aug 21, 20207.624NONO
CVE-2018-5717HIGH
Memory write mechanism in NCR S2 Dispenser controller before firmware version 0x0108 allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to
Mar 20, 20187.524NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
19%
38%
38%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (61.9%)
Unknown3 (14.3%)
Physical5 (23.8%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (81.0%)
High1 (4.8%)
Unknown3 (14.3%)
User Interaction
None18 (85.7%)
Unknown3 (14.3%)
Required0 (0.0%)
Privileges Required
Low3 (14.3%)
High0 (0.0%)
None15 (71.4%)
Unknown3 (14.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.8% of CVEs· 98th percentile
Nuclei
1 CVE
4.8% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ncr.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ncr — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ncr's Products

View all 2 CNAs →

Top CWEs