← Back

CVE-2020-10124

nvd nist
Published: Aug 21, 2020Modified: Nov 4, 2025

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 0.5 / Impact: 6.0
Source: NVD

Description

NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal components of the ATM to execute arbitrary code, including code that enables the attacker to commit deposit forgery.

Affected (1)

Products: Ncr: Aptra Xfs
1 product
Aptra Xfs
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 05.01.00
Running on/withPlatform Versions
Ncr
Selfserv Atm
All versions

References (5)

Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.