CVE-2020-10124
Estado: ModificadaAlta (7.1)—
NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal components of the ATM to execute arbitrary code, including code that enables the attacker to commit deposit forgery.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.73%
- Percentil entre todas las CVEs puntuadas: 53
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-306, CWE-311, CWE-353
- CWE-319
Referencias
- https://kb.cert.org/vuls/id/815655
- https://www.ncr.com/content/dam/ncrcom/content-type/documents/NCR_Security_Alert-2018-13_APTRA_XFS_
- https://kb.cert.org/vuls/id/815655
- https://www.kb.cert.org/vuls/id/815655
- https://www.ncr.com/content/dam/ncrcom/content-type/documents/NCR_Security_Alert-2018-13_APTRA_XFS_
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-10124",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.4,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "PHYSICAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 0.5
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "NCR",
"product": "SelfServ ATM",
"versions": [
{
"status": "affected",
"version": "APTRA XFS 05.01.00"
}
]
}
]
}
],
"published": "2020-08-21T21:15:11.433",
"references": [
{
"url": "https://kb.cert.org/vuls/id/815655",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "https://www.ncr.com/content/dam/ncrcom/content-type/documents/NCR_Security_Alert-2018-13_APTRA_XFS_",
"tags": [
"Broken Link"
],
"source": "cret@cert.org"
},
{
"url": "https://kb.cert.org/vuls/id/815655",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.kb.cert.org/vuls/id/815655",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.ncr.com/content/dam/ncrcom/content-type/documents/NCR_Security_Alert-2018-13_APTRA_XFS_",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cret@cert.org",
"description": [
{
"lang": "en",
"value": "CWE-306"
},
{
"lang": "en",
"value": "CWE-311"
},
{
"lang": "en",
"value": "CWE-353"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal components of the ATM to execute arbitrary code, including code that enables the attacker to commit deposit forgery."
},
{
"lang": "es",
"value": "Los Cajeros Automáticos NCR SelfServ que ejecutan APTRA XFS versiones 05.01.00 no cifran, ni autentican, ni verifican la integridad de los mensajes entre el BNA y el computador host, lo que podría permitir a un atacante con acceso físico a los componentes internos del Cajero Automático ejecutar código arbitrario, incluyendo código que permite al atacante cometer falsificaciones de depósitos."
}
],
"lastModified": "2026-06-17T02:47:24.307",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ncr:aptra_xfs:05.01.00:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "488456FE-C4C8-43D6-B6A2-5BFC3EC076EC"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ncr:selfserv_atm:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B95CF58A-28C7-4C1E-8B83-7BF0D515FF34"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cret@cert.org"
}