Vulnerability record · CVE-2021-3122 · published 7 February 2021
CVE-2021-3122: NCR Command Center Agent unauthenticated OS command injection
Ncr · Command Center Agent
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers accepts a runCommand parameter inside an XML document sent to port 8089, allowing remote unauthenticated command execution as SYSTEM. The flaw is an OS command injection (CWE-78) with a critical CVSS 3.1 score of 9.8, and the description states it was exploited in the wild in 2020 and/or 2021. The vendor disputes scope, claiming exploitation only occurs on devices with a certain misconfiguration.
Description
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as exploited in the wild in 2020 and/or 2021. NOTE: the vendor's position is that exploitation occurs only on devices with a certain "misconfiguration."
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution as SYSTEM with a 9.8 CVSS score and reported in-the-wild exploitation makes this an urgent patch-first issue.
What it is
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers accepts a runCommand parameter inside an XML document sent to port 8089, allowing remote unauthenticated command execution as SYSTEM. The flaw is an OS command injection (CWE-78) with a critical CVSS 3.1 score of 9.8, and the description states it was exploited in the wild in 2020 and/or 2021. The vendor disputes scope, claiming exploitation only occurs on devices with a certain misconfiguration.
Impact
An attacker gains arbitrary command execution with SYSTEM privileges on the affected Aloha POS/BOH server, giving full control of the host and any data or payment processing it handles.
Attack surface
Reachable over the network via an XML document submitted to port 8089; the CVSS vector shows no privileges and no user interaction required, so it is unauthenticated and remotely triggerable.
Exploitation
The description states it was exploited in the wild in 2020 and/or 2021, and EPSS is very high at 0.8727 (99.7th percentile), though it is not listed in CISA KEV and no ransomware group is documented.
What to do
- Apply the vendor fix or upgrade NCR Command Center Agent beyond the affected 16.3 build; confirm the vendor's misconfiguration guidance with NCR support.
- Restrict network access to TCP port 8089 so only trusted management hosts can reach CMCAgent.
- Remove or disable the CMCAgent service where it is not required on Aloha POS/BOH servers.
- Segment POS and BOH networks from general corporate and internet-facing networks to limit reach.
- Monitor for unexpected SYSTEM-level child processes spawned by CMCAgent.
Detection
- Alert on inbound connections to TCP port 8089 from outside expected management subnets.
- Inspect XML payloads to port 8089 for a runCommand parameter or command-like strings.
- Hunt for CMCAgent spawning cmd.exe, powershell.exe or other shells as SYSTEM.
- Review host logs for anomalous SYSTEM-level process creation on Aloha POS/BOH servers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/roughb8722/CVE-2021-3122-Details/blob/main/CVE-2021-3122 | Third Party Advisory |
| https://rdf2.alohaenterprise.com/client/CMCInst.zip | Third Party Advisory |
| https://www.tetradefense.com/incident-response-services/active-exploit-a-remote-code-execution-rce-vulnerability-for-ncr | Third Party Advisory |
| https://github.com/roughb8722/CVE-2021-3122-Details/blob/main/CVE-2021-3122 | Third Party Advisory |
| https://rdf2.alohaenterprise.com/client/CMCInst.zip | Third Party Advisory |
| https://www.tetradefense.com/incident-response-services/active-exploit-a-remote-code-execution-rce-vulnerability-for-ncr | Third Party Advisory |
Track CVE-2021-3122 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-3122), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.