CVE Vulnerabilities

CVE-2020-10125

Inadequate Encryption Strength

Published: Aug 21, 2020 | Modified: Aug 27, 2020
CVSS 3.x
7.6
HIGH
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

NCR SelfServ ATMs running APTRA XFS 04.02.01 and 05.01.00 implement 512-bit RSA certificates to validate bunch note acceptor (BNA) software updates, which can be broken by an attacker with physical access in a sufficiently short period of time, thereby enabling the attacker to sign arbitrary files and CAB archives used to update BNA software, as well as bypass application whitelisting, resulting in the ability to execute arbitrary code.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
Aptra_xfs Ncr 04.02.01 (including) 04.02.01 (including)
Aptra_xfs Ncr 05.01.00 (including) 05.01.00 (including)

Potential Mitigations

References