CVE-2020-10123 - CVE House
Back to Database
Status published Medium CVE-2020-10123

The currency dispenser of NCR SelfSev ATMs running APTRA XFS...

Vulnerability Description

The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not adequately authenticate session key generation requests from the host computer, allowing an attacker with physical access to internal ATM components to issue valid commands to dispense currency by generating a new session key that the attacker knows.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-10123

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SelfServ ATM
Vulnerable Versions:
APTRA XFS

Timeline

Official Publish: August 21st, 2020
Last Modified: November 4th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.