CVE-2013-2571

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
28/01/2020
Last modified:
06/02/2020

Description

Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcomm:xpient_iris:*:*:*:*:*:*:*:* 3.8 (including)