Learn about CVE-2020-9062 affecting Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase 1.1.30. Discover the impact, technical details, and mitigation steps.
Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 have vulnerabilities that could allow attackers to manipulate deposit transactions.
Understanding CVE-2020-9062
Diebold Nixdorf ProCash 2100xe USB ATMs are susceptible to deposit forgery due to a lack of message encryption, authentication, and integrity verification.
What is CVE-2020-9062?
This CVE refers to the security issue in Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30, enabling attackers to tamper with deposit messages.
The Impact of CVE-2020-9062
The vulnerability allows attackers with physical access to the ATM components to intercept and modify messages to the host computer, potentially altering deposited currency values.
Technical Details of CVE-2020-9062
Diebold Nixdorf ProCash 2100xe USB ATMs are affected by several critical weaknesses.
Vulnerability Description
The ATMs lack encryption, authentication, and integrity verification for messages between the CCDM and the host computer, facilitating deposit forgery.
Affected Systems and Versions
Exploitation Mechanism
Attackers can exploit the lack of message security to intercept and modify deposit-related messages, potentially altering the deposited amount and currency value.
Mitigation and Prevention
It is crucial to take immediate and long-term security measures to address CVE-2020-9062.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates