Search/CVE-2020-9063
CVE — High

CVE-2020-9063

NCR SelfServ ATMs running APTRA XFS 05.01.00 or earlier do not authenticate or protect the integrity of USB HID communications between the currency dispenser and the host computer, permitting an attacker with physical access to internal ATM components the ability to inject a malicious payload and execute arbitrary code with SYSTEM privileges on the host computer by causing a buffer overflow on the host.

CVSS v3.1
7.6 HIGH
EPSS
0.67%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
CVSS v3.1 Detail
Attack VectorPHYSICAL
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Connections
2 relationships
Timeline
disclosure → media coverage
Aug 21, 2020
Disclosure — published as a CVE record. · last revised by NVD Nov 4, 2025