Vulnerability Description
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal components of the ATM to execute arbitrary code, including code that enables the attacker to commit deposit forgery.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ncr | Aptra Xfs | 05.01.00 |
| Ncr | Selfserv Atm | - |
Related Weaknesses (CWE)
References
- https://kb.cert.org/vuls/id/815655Third Party AdvisoryUS Government Resource
- https://www.ncr.com/content/dam/ncrcom/content-type/documents/NCR_Security_AlertBroken Link
- https://kb.cert.org/vuls/id/815655Third Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/815655
- https://www.ncr.com/content/dam/ncrcom/content-type/documents/NCR_Security_AlertBroken Link
FAQ
What is CVE-2020-10124?
CVE-2020-10124 is a vulnerability with a CVSS score of 7.1 (HIGH). NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access...
How severe is CVE-2020-10124?
CVE-2020-10124 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10124?
Check the references section above for vendor advisories and patch information. Affected products include: Ncr Aptra Xfs, Ncr Selfserv Atm.