CVE-2020-10124 Vulnerability Details

  /     /     /  

CVE-2020-10124 Metadata Quick Info

CVE Published: 21/08/2020 | CVE Updated: 17/09/2024 | CVE Year: 2020
Source: certcc | Vendor: NCR | Product: SelfServ ATM
Status : PUBLISHED

CVE-2020-10124 Description

NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal components of the ATM to execute arbitrary code, including code that enables the attacker to commit deposit forgery.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-353
CWE Name: CWE-353 Missing Support for Integrity Check
Source: NCR

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).