CVE-2020-10124
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal components of the ATM to execute…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal components of the ATM to execute arbitrary code, including code that enables the attacker to commit deposit forgery.
- CVSS 3.1
- 7.1 HIGHCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.73% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306, CWE-311, CWE-353, CWE-319
- Affected
- ncr/aptra xfs
- Source
- cret@cert.org
References
- https://kb.cert.org/vuls/id/815655Third Party Advisory, US Government Resource
- https://www.ncr.com/content/dam/ncrcom/content-type/documents/NCR_Security_Alert-2018-13_APTRA_XFS_Broken Link
- https://kb.cert.org/vuls/id/815655Third Party Advisory, US Government Resource
- https://www.kb.cert.org/vuls/id/815655
- https://www.ncr.com/content/dam/ncrcom/content-type/documents/NCR_Security_Alert-2018-13_APTRA_XFS_Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.