CVE-2020-10124: High severity xfs acl vulnerability
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal components of the ATM to execute arbitrary code, including code that enables the attacker to commit deposit forgery.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10124?
CVE-2020-10124 is classified as a critical vulnerability due to its potential for arbitrary code execution by an attacker with physical access to the ATM.
How do I fix CVE-2020-10124?
To mitigate CVE-2020-10124, upgrade the NCR APTRA XFS software to a version that incorporates message encryption and authentication.
What systems are affected by CVE-2020-10124?
CVE-2020-10124 affects NCR SelfServ ATMs running APTRA XFS version 05.01.00.
Can CVE-2020-10124 be exploited remotely?
CVE-2020-10124 requires physical access to the ATM for exploitation, making remote attacks unlikely.
What are the potential impacts of CVE-2020-10124?
Exploitation of CVE-2020-10124 may enable attackers to execute arbitrary code on the ATM, potentially leading to unauthorized access and financial theft.