ATM Makers Diebold And NCR Deploy Fixes For 'deposit Forgery' Attacks

Two of today's biggest ATM manufacturers, Diebold Nixdorf and NCR, have released software updates to address bugs that could have been exploited for "deposit forgery" attacks.

Deposit forgery attacks happen when fraudsters can tamper with an ATM's software to modify the amount and value of currency being deposited on a payment card.

Such attacks are usually followed by quick cash withdrawals, either during weekends or via transactions at other banks, with the fraudsters trying to capitalize on the inexistent funds before banks detect any errors in account balances.

Two similar bugs impact Diebold Nixdorf and NCR ATMs

Deposit forgery bugs are rare, but two have been discovered last year and patched this year. Diebold Nixdorf patched CVE-2020-9062, an issue impacting ProCash 2100xe USB ATMs running Wincor Probase software, while NCR patched CVE-2020-10124, a bug in SelfServ ATMs running APTRA XFS software.

At their core, both bugs are identical, according to advisories published today by the CERT Coordination Center at Carnegie Mellon University.

CERT/CC says the ATMs do not encrypt, authenticate, or verify the integrity of messages sent between the ATM cash deposit boxes and the host computer.

An attacker that has physical access to connect to the ATM can tamper with these messages when cash is deposited and artificially inflate the deposited funds.

Diebold and NCR have secured their devices by releasing software updates that have hardened the communications between the cash deposit module and the host computer.

Both vulnerabilities, and others, have been discovered by security researchers working at Embedi, a Moscow-based security firm that was sanctioned by the US Treasury Department in June 2018 for allegedly working with the Federal Security Service (FSB), Russia's top intelligence agency, to bolster Russia's "offensive cyber capabilities."

Before working with Embedi researchers on coordinating the public disclosure of these bugs, the CERT/CC at CMU had to obtain a special permit from the Office of Foreign Assets Control (OFAC) at the US Treasury Department.

RECENT NEWS

Reassessing AI Investments: What The Correction In US Megacap Tech Stocks Signals

The recent correction in US megacap tech stocks, including giants like Nvidia, Tesla, Meta, and Alphabet, has sent rippl... Read more

AI Hype Meets Reality: Assessing The Impact Of Stock Declines On Future Tech Investments

Recent declines in the stock prices of major tech companies such as Nvidia, Tesla, Meta, and Alphabet have highlighted a... Read more

Technology Sector Fuels U.S. Economic Growth In Q2

The technology sector played a pivotal role in accelerating America's economic growth in the second quarter of 2024.The ... Read more

Tech Start-Ups Advised To Guard Against Foreign Investment Risks

The US National Counterintelligence and Security Center (NCSC) has advised American tech start-ups to be wary of foreign... Read more

Global IT Outage Threatens To Cost Insurers Billions

Largest disruption since 2017’s NotPetya malware attack highlights vulnerabilities.A recent global IT outage has cause... Read more

Global IT Outage Disrupts Airlines, Financial Services, And Media Groups

On Friday morning, a major IT outage caused widespread disruption across various sectors, including airlines, financial ... Read more