Fiserv Originate Loans Peripherals Print Service .NET Remoting Remote Code Execution Vulnerability
Vulnerability
A remote code execution vulnerability exists in the Print Service component of Fiserv Originate Loans Peripherals, specifically in the unsupported version 2021.2.4 (build 4.7.3155.0011). This vulnerability arises from the use of deprecated .NET Remoting TCP channels, which allow unsafe deserialization of untrusted data. In client-managed deployments where these services are exposed to an untrusted network, an unauthenticated attacker can exploit this flaw to execute arbitrary code remotely.
Impact
Exploitation of this vulnerability allows for remote code execution on the affected system.
Remediation
Users are advised to upgrade to a currently supported release (2025.1 or later) and ensure that .NET Remoting service ports are not exposed beyond trusted network boundaries.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
