CVE-2023-28865

EUVD-2023-32486
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory contents of certain directories (e.g., ensuring the expected hash sum) during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.6 MEDIUM
PHYSICAL
LOW
LOW
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
dieboldnixdorfvynamic_security_suite
𝑥
< 3.3.0sr15
dieboldnixdorfvynamic_security_suite
4.0.0 ≤
𝑥
< 4.0.0sr05
dieboldnixdorfvynamic_security_suite
4.1.0 ≤
𝑥
< 4.1.0sr03
dieboldnixdorfvynamic_security_suite
4.2.0 ≤
𝑥
< 4.2.0sr02
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
dieboldnixdorfvynamic_security_suite
3.3.0 ≤
𝑥
≤ 3.3.0sr14
ADP
dieboldnixdorfvynamic_security_suite
3.3.0sr14 ≤
𝑥
< 4.0.0sr05
ADP
dieboldnixdorfvynamic_security_suite
3.3.0sr14 ≤
𝑥
< 4.1.0.sr03
ADP
dieboldnixdorfvynamic_security_suite
3.3.0sr14 ≤
𝑥
< 4.2.0sr02
ADP