← Back

CVE-2020-10125

nvd nist
Published: Aug 21, 2020Modified: Nov 4, 2025

JSON object

Loading...
7.6
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 6.0
Source: NVD

Description

NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acceptor (BNA) software updates, which can be broken by an attacker with physical access in a sufficiently short period of time, thereby enabling the attacker to sign arbitrary files and CAB archives used to update BNA software, as well as bypass application whitelisting, resulting in the ability to execute arbitrary code.

Affected (2)

Products: Ncr: Aptra Xfs
1 product
Aptra Xfs
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Ncr
Version 04.02.01
Version 05.01.00
Running on/withPlatform Versions
Ncr
Selfserv Atm
All versions

References (5)

Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.