PT-2020-11945 · Ncr · Aptra Xfs+1

Maxim Kozorez

·

Published

2020-08-21

·

Updated

2025-11-04

·

CVE-2020-10123

CVSS v3.1

5.3

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions NCR SelfSev ATMs running APTRA XFS version 05.01.00 or earlier
Description The issue concerns inadequate authentication of session key generation requests from the host computer in the currency dispenser of NCR SelfSev ATMs. This allows an attacker with physical access to internal ATM components to issue valid commands to dispense currency by generating a new session key that the attacker knows.
Recommendations For NCR SelfSev ATMs running APTRA XFS version 05.01.00 or earlier, consider restricting physical access to internal ATM components to minimize the risk of exploitation. As a temporary workaround, review and enhance the authentication process for session key generation requests from the host computer until a more permanent fix is available.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10123

Affected Products

Aptra Xfs
Ncr Selfserv Atms