2.1
CVSSv2

CVE-2020-10123

Published: 21/08/2020 Updated: 27/08/2020
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.3 | Impact Score: 4 | Exploitability Score: 0.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate session key generation requests from the host computer, allowing an attacker with physical access to internal ATM components to issue valid commands to dispense currency by generating a new session key that the attacker knows.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ncr aptra_xfs