MEDIUM
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR02 fails to validate file attributes during the Pre-Boot Authorization (PBA) process
Published Aug 8, 2024
6.8
MEDIUMCVSS 3.1
EPSS 0.36%
Description
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR02 fails to validate file attributes during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.
Affected products
No data.
OR
- < 3.3.0sr17
- ≥ 4.0.0 · < 4.0.0sr07
- ≥ 4.1.0 · < 4.1.0sr04
- ≥ 4.2.0 · < 4.2.0sr04
- ≥ 4.3.0 · < 4.3.0sr03
-
- Version 3.3.0StatusaffectedConstraints<=3.3.0sr16
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Dieboldnixdorf | Vynamic Security Suite | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44858 Advisory
- https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Matt%20Burch%20-%20Where%E2%80%99s%20the%20Money%20-%20Defeating%20ATM%20Disk%20Encryption-white%20paper.pdf ExploitThird Party Advisory
- https://www.dieboldnixdorf.com/en-us/banking/portfolio/software/security/ Vendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 8, 2024
Updated Mar 13, 2025
Reserved Aug 11, 2023
Link CVE-2023-40261
CISA Vulnrichment
Updated Aug 9, 2024
ENISA EUVD
EUVD-2023-44858 Assigner mitre
Published Aug 8, 2024
Updated Mar 13, 2025
Exploited since n/a
Link EUVD-2023-44858