VYPR
Medium severity5.3NVD Advisory· Published Aug 21, 2020· Updated Jun 17, 2026

CVE-2020-10123

CVE-2020-10123

Description

The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate session key generation requests from the host computer, allowing an attacker with physical access to internal ATM components to issue valid commands to dispense currency by generating a new session key that the attacker knows.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Ncr/Aptra Xfs2 versions
    cpe:2.3:o:ncr:aptra_xfs:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:ncr:aptra_xfs:*:*:*:*:*:*:*:*range: <=05.01.00
    • (no CPE)range: <=05.01.00
  • Ncr/SelfServ ATMscpe-rescue
    Range: APTRA XFS

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.