Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory contents of certain directories (e.g., ensuring the expected hash sum) during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.
Metrics
Affected Vendors & Products
References
History
Mon, 19 Aug 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-345 |
Thu, 08 Aug 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dieboldnixdorf
Dieboldnixdorf vynamic Security Suite |
|
Weaknesses | CWE-353 | |
CPEs | cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:*:*:*:*:*:*:*:* | |
Vendors & Products |
Dieboldnixdorf
Dieboldnixdorf vynamic Security Suite |
|
Metrics |
cvssV3_1
|
Thu, 08 Aug 2024 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory contents of certain directories (e.g., ensuring the expected hash sum) during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-08-08T00:00:00
Updated: 2024-08-08T20:09:23.502Z
Reserved: 2023-03-26T00:00:00
Link: CVE-2023-28865
Vulnrichment
Updated: 2024-08-08T20:09:10.339Z
NVD
Status : Analyzed
Published: 2024-08-08T18:15:09.533
Modified: 2024-08-19T19:04:14.230
Link: CVE-2023-28865
Redhat
No data.