Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root during integrity validation. This allows code execution, recovery of TPM Disk Encryption keys, decryption of the Windows system partition, and full control of the Windows OS, e.g., through ~/.profile changes.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:*:*:*:*:*:*:*:* |
Mon, 01 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dieboldnixdorf
Dieboldnixdorf vynamic Security Suite |
|
| Vendors & Products |
Dieboldnixdorf
Dieboldnixdorf vynamic Security Suite |
Fri, 29 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-353 | |
| Metrics |
cvssV3_1
|
Fri, 29 Aug 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root during integrity validation. This allows code execution, recovery of TPM Disk Encryption keys, decryption of the Windows system partition, and full control of the Windows OS, e.g., through ~/.profile changes. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-08-29T00:00:00.000Z
Updated: 2025-08-29T17:32:46.785Z
Reserved: 2024-09-15T00:00:00.000Z
Link: CVE-2024-46917
Updated: 2025-08-29T17:31:04.793Z
Status : Analyzed
Published: 2025-08-29T16:15:35.750
Modified: 2025-09-09T14:02:46.770
Link: CVE-2024-46917
No data.
ReportizFlow