CVE-2020-10123: Medium severity xfs acl vulnerability
The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate session key generation requests from the host computer, allowing an attacker with physical access to internal ATM components to issue valid commands to dispense currency by generating a new session key that the attacker knows.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10123?
CVE-2020-10123 has a high severity rating due to the potential for unauthorized currency dispensing through physical access.
How do I fix CVE-2020-10123?
To mitigate CVE-2020-10123, it is recommended to upgrade NCR SelfServ ATMs to APTRA XFS version later than 05.01.00.
What systems are affected by CVE-2020-10123?
CVE-2020-10123 affects NCR SelfServ ATMs running APTRA XFS 05.01.00 or earlier.
Can attackers exploit CVE-2020-10123 remotely?
No, attackers need physical access to the ATM components to exploit CVE-2020-10123.
What type of vulnerability is CVE-2020-10123?
CVE-2020-10123 is an authentication vulnerability in currency dispensers of affected NCR SelfServ ATMs.