ASA 019-23-0001 Potential Remote Code Execution On Opteva Terminals
ASA 019-23-0001 Potential Remote Code Execution On Opteva Terminals
Summary
Diebold Nixdorf was recently informed about a potential remote code execution on Opteva terminals. The
potential exposure was a part of the Agilis XFS service using .Net remoting over an externally facing http
channel.
While all Opteva systems come equipped with a terminal-based firewall installed, from the information we
have, the terminal based firewall of the system was most likely not active during the evaluation.
We have not received any reports of this potential exposure being exploited outside of a test environment.
dŚŝƐŝŶĨŽƌŵĂƚŝŽŶŝƐĐŽŶĨŝĚĞŶƚŝĂůĂŶĚŵĂLJďĞůĞŐĂůůLJƉƌŝǀŝůĞŐĞĚ͘/ĨLJŽƵĂƌĞŶŽƚƚŚĞŝŶƚĞŶĚĞĚƌĞĐŝƉŝĞŶƚ͕ĂŶLJĚŝƐĐůŽƐƵƌĞ͕ĐŽƉLJŝŶŐ͕
ŽƌĚŝƐƚƌŝďƵƚŝŽŶŝƐƉƌŽŚŝďŝƚĞĚ͘
ΞϮϬϭϵŝĞďŽůĚEŝdžĚŽƌĨ͕ĂůůƌŝŐŚƚƐƌĞƐĞƌǀĞĚ h^dKDZKE&/Ed/>
Corporate Product & Solution Security
For detailed information, please contact your local sales department, a hardware integration
representative or your Diebold Nixdorf security expert.
Check out the Diebold Nixdorf Security blogs: Subscribe to the Global Security Portal:
https://blog.dieboldnixdorf.com/category/security/ https://gsp.dieboldnixdorf.com/
dŚŝƐŝŶĨŽƌŵĂƚŝŽŶŝƐĐŽŶĨŝĚĞŶƚŝĂůĂŶĚŵĂLJďĞůĞŐĂůůLJƉƌŝǀŝůĞŐĞĚ͘/ĨLJŽƵĂƌĞŶŽƚƚŚĞŝŶƚĞŶĚĞĚƌĞĐŝƉŝĞŶƚ͕ĂŶLJĚŝƐĐůŽƐƵƌĞ͕ĐŽƉLJŝŶŐ͕
ŽƌĚŝƐƚƌŝďƵƚŝŽŶŝƐƉƌŽŚŝďŝƚĞĚ͘
ΞϮϬϭϵŝĞďŽůĚEŝdžĚŽƌĨ͕ĂůůƌŝŐŚƚƐƌĞƐĞƌǀĞĚ h^dKDZKE&/Ed/>