PT-2020-11945 · Ncr · Aptra Xfs+1
Maxim Kozorez
·
Published
2020-08-21
·
Updated
2025-11-04
·
CVE-2020-10123
CVSS v3.1
5.3
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
NCR SelfSev ATMs running APTRA XFS version 05.01.00 or earlier
Description
The issue concerns inadequate authentication of session key generation requests from the host computer in the currency dispenser of NCR SelfSev ATMs. This allows an attacker with physical access to internal ATM components to issue valid commands to dispense currency by generating a new session key that the attacker knows.
Recommendations
For NCR SelfSev ATMs running APTRA XFS version 05.01.00 or earlier, consider restricting physical access to internal ATM components to minimize the risk of exploitation. As a temporary workaround, review and enhance the authentication process for session key generation requests from the host computer until a more permanent fix is available.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aptra Xfs
Ncr Selfserv Atms