← Vulnerability feed

Vulnerability record · CVE-2021-3122 · published 7 February 2021

CVE-2021-3122: NCR Command Center Agent unauthenticated OS command injection

Ncr · Command Center Agent

CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers accepts a runCommand parameter inside an XML document sent to port 8089, allowing remote unauthenticated command execution as SYSTEM. The flaw is an OS command injection (CWE-78) with a critical CVSS 3.1 score of 9.8, and the description states it was exploited in the wild in 2020 and/or 2021. The vendor disputes scope, claiming exploitation only occurs on devices with a certain misconfiguration.

9.8 CVSS 3.1 Critical EPSS 87% · top 0.3% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as exploited in the wild in 2020 and/or 2021. NOTE: the vendor's position is that exploitation occurs only on devices with a certain "misconfiguration."

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution as SYSTEM with a 9.8 CVSS score and reported in-the-wild exploitation makes this an urgent patch-first issue.

What it is

CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers accepts a runCommand parameter inside an XML document sent to port 8089, allowing remote unauthenticated command execution as SYSTEM. The flaw is an OS command injection (CWE-78) with a critical CVSS 3.1 score of 9.8, and the description states it was exploited in the wild in 2020 and/or 2021. The vendor disputes scope, claiming exploitation only occurs on devices with a certain misconfiguration.

Impact

An attacker gains arbitrary command execution with SYSTEM privileges on the affected Aloha POS/BOH server, giving full control of the host and any data or payment processing it handles.

Attack surface

Reachable over the network via an XML document submitted to port 8089; the CVSS vector shows no privileges and no user interaction required, so it is unauthenticated and remotely triggerable.

Exploitation

The description states it was exploited in the wild in 2020 and/or 2021, and EPSS is very high at 0.8727 (99.7th percentile), though it is not listed in CISA KEV and no ransomware group is documented.

What to do

  • Apply the vendor fix or upgrade NCR Command Center Agent beyond the affected 16.3 build; confirm the vendor's misconfiguration guidance with NCR support.
  • Restrict network access to TCP port 8089 so only trusted management hosts can reach CMCAgent.
  • Remove or disable the CMCAgent service where it is not required on Aloha POS/BOH servers.
  • Segment POS and BOH networks from general corporate and internet-facing networks to limit reach.
  • Monitor for unexpected SYSTEM-level child processes spawned by CMCAgent.

Detection

  • Alert on inbound connections to TCP port 8089 from outside expected management subnets.
  • Inspect XML payloads to port 8089 for a runCommand parameter or command-like strings.
  • Hunt for CMCAgent spawning cmd.exe, powershell.exe or other shells as SYSTEM.
  • Review host logs for anomalous SYSTEM-level process creation on Aloha POS/BOH servers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-3122 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed7.8CVE-2026-53362Linux kernel IPv6 UDP paged allocation out-of-bounds write__ip6_append_data() in the Linux kernel mis-accounts fraggap on the paged-allocation path, leaving the linear skb area undersized while pagedlen is o…KEVEPSS 0.71%analysed7.8CVE-2022-0995Linux kernel watch_queue out-of-bounds writeThe Linux kernel's watch_queue event notification subsystem contains an out-of-bounds write (CWE-787) that can overwrite kernel state. A local user c…KEVEPSS 8.8%analysed8.9CVE-2026-73570Zimbra Collaboration SNMP notification OS command injectionZimbra Collaboration Suite before 10.1.20 contains an OS command injection flaw in SNMP notification processing when the optional zimbra-snmp package…KEVEPSS 12%analysed

Source: NIST National Vulnerability Database (record CVE-2021-3122), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.