CVE-2013-2571
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 16%
from disclosure to weapon0 days
Published on NVDJan 28
1st PoCJun 5
exploitation probability
16%top 3% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/121917/Xpient-POS-Iris-3.8-Cash-Drawer-Operation-Remote-Trigger.htmlunverifiedcve_referencewww.exploit-db.com/exploits/25987unverifiedexploitdbwww.exploit-db.com/exploits/25987unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.