Vulnerability Description
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA), enabling an attacker with physical access to internal ATM components to restart the host computer and execute arbitrary code with SYSTEM privileges because while booting, the update process looks for CAB archives on removable media and executes a specific file without first validating the signature of the CAB archive.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ncr | Aptra Xfs | 05.01.00 |
| Ncr | Selfserv Atm | - |
Related Weaknesses (CWE)
References
- https://kb.cert.org/vuls/id/815655Third Party AdvisoryUS Government Resource
- https://www.ncr.com/content/dam/ncrcom/content-type/documents/NCR_Security_AlertBroken Link
- https://kb.cert.org/vuls/id/815655Third Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/815655
- https://www.ncr.com/content/dam/ncrcom/content-type/documents/NCR_Security_AlertBroken Link
FAQ
What is CVE-2020-10126?
CVE-2020-10126 is a vulnerability with a CVSS score of 7.6 (HIGH). NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note acceptor (BNA), enabling an attacker with physical access to internal ATM components to restart...
How severe is CVE-2020-10126?
CVE-2020-10126 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10126?
Check the references section above for vendor advisories and patch information. Affected products include: Ncr Aptra Xfs, Ncr Selfserv Atm.