CRITICAL

CVE-2013-2571

CVSS v3

9.8

CRITICAL

EPSS Score

62.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer.

Technical details

Published
1/28/2020
Exploit-DB
EDB-25987

Frequently asked questions

What is CVE-2013-2571?

Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer.

Is CVE-2013-2571 actively exploited?

Active exploitation of CVE-2013-2571 has not been confirmed. The EPSS score is 62.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2013-2571?

CVE-2013-2571 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2013-2571 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

Other 2013 vulnerabilities worth triaging

Ranked by exploit probability (EPSS).