PT-2020-11948 · Ncr · Aptra Xfs+1
Dmitry Turchenkov
+1
·
Published
2020-08-21
·
Updated
2025-11-04
·
CVE-2020-10126
CVSS v3.1
7.6
High
| Vector | AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NCR SelfServ ATMs running APTRA XFS version 05.01.00
Description
The issue concerns a lack of proper validation for software updates related to the bunch note acceptor (BNA) in NCR SelfServ ATMs. This allows an attacker with physical access to internal ATM components to restart the host computer and execute arbitrary code with SYSTEM privileges. The vulnerability is exploited during the boot process when the update mechanism searches for CAB archives on removable media and executes a specific file without validating the CAB archive's signature.
Recommendations
For NCR SelfServ ATMs running APTRA XFS version 05.01.00, consider restricting physical access to internal ATM components to minimize the risk of exploitation. As a temporary workaround, avoid using removable media for updates until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aptra Xfs
Ncr Selfserv Atms