HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2020-9063

CVSS 7.6v3.1pub. 2020-08-21upd. 2025-11-04

NCR SelfServ ATMs running APTRA XFS 05.01.00 or earlier do not authenticate or protect the integrity of USB HID communications between the currency dispenser and the host computer, permitting an attacker with physical access to internal ATM components the ability to inject a malicious payload and execute arbitrary code with SYSTEM privileges on the host computer by causing a buffer overflow on the host.

CVSS Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Ncr Aptra Xfs

    OS
    Ncr
    ≤ 05.01.00
  • Ncr Selfserv Atm

    HW
    Ncr
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2020-10124HIGH7.1same product

NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages...

CVE-2020-10125HIGH7.6same product

NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch...

CVE-2020-10126HIGH7.6same product

NCR SelfServ ATMs running APTRA XFS 05.01.00 do not properly validate softare updates for the bunch note accep...

CVE-2020-10123MEDIUM5.3same product

The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authentic...

CVE-2023-47029CRITICAL9.8PL ✓same vendor

RCE i wyciek danych w NCR Terminal Handler przez komponent UserService