CVE-2020-10123

MEDIUM

NCR SelfSev APTRA XFS <05.01.00 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate session key generation requests from the host computer, allowing an attacker with physical access to internal ATM components to issue valid commands to dispense currency by generating a new session key that the attacker knows.

Scores

CVSS v3 5.3
EPSS 0.0010
EPSS Percentile 28.0%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Details

CWE
CWE-305 CWE-287
Status published
Products (1)
ncr/aptra_xfs < 05.01.00
Published Aug 21, 2020
Tracked Since Feb 18, 2026