CVE-2025-61429

8.8

NCR Atleos · Terminal Manager (ConfigApp)

NCR Atleos Terminal Manager (ConfigApp) version 3.4.0 contains a vulnerability that allows authenticated attackers to escalate their privileges through a specially crafted request.

Executive summary

A privilege escalation vulnerability in NCR Atleos Terminal Manager version 3.4.0 poses a high risk of unauthorized administrative control over the application.

Vulnerability

The application is susceptible to privilege escalation due to insufficient validation of requests, allowing an authenticated user to gain higher-level permissions. The attack vector is network-based and requires the attacker to possess low-level user privileges to initiate the exploit.

Business impact

The ability for a standard user to escalate privileges to an administrative level creates a significant security risk, potentially leading to unauthorized data access, system configuration changes, or complete compromise of the terminal management environment. With a CVSS score of 8.8, this flaw is categorized as High severity, reflecting the potential for full confidentiality, integrity, and availability impact within the application context.

Remediation

Immediate Action: Contact NCR Atleos support or monitor their official security portal to obtain the latest security patch or configuration guidance for ConfigApp version 3.4.0.

Proactive Monitoring: Review audit logs for unusual administrative activity or unexpected privilege changes associated with standard user accounts.

Compensating Controls: Implement strict network segmentation to limit access to the Terminal Manager interface to authorized personnel only, and utilize Web Application Firewalls to inspect traffic for malicious request patterns.

Exploitation status

Public Exploit Available: Yes — a published proof-of-concept exists as documented in the referenced security research.

Analyst recommendation

Given the High severity of this privilege escalation flaw and the confirmed existence of proof-of-concept material, organizations must treat this as a priority remediation item. Security teams should verify their current version of ConfigApp and coordinate with the vendor to ensure the latest protections are applied immediately to prevent unauthorized system elevation.

Sources