CVE-2020-9062
Summary
| CVE | CVE-2020-9062 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-21 21:15:00 UTC |
| Updated | 2020-08-27 19:36:00 UTC |
| Description | Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messages between the CCDM and the host computer, allowing an attacker with physical access to internal ATM components to commit deposit forgery by intercepting and modifying messages to the host computer, such as the amount and value of currency being deposited. |
Risk And Classification
Problem Types: CWE-306 | CWE-311
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dieboldnixdorf | Probase | 1.1.30 | All | All | All |
| Application | Dieboldnixdorf | Probase | 1.1.30 | All | All | All |
| Hardware | Dieboldnixdorf | Procash 2100xe | - | All | All | All |
| Hardware | Dieboldnixdorf | Procash 2100xe | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VU#221785 - Diebold Nixdorf ProCash 2100xe USB ATM does not adequately secure communications between CCDM and host | MISC | kb.cert.org | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.