6.8

CVE-2023-40261

Exploit
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR02 fails to validate file attributes during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DieboldnixdorfVynamic Security Suite Version < 3.3.0sr17
DieboldnixdorfVynamic Security Suite Version >= 4.0.0 < 4.0.0sr07
DieboldnixdorfVynamic Security Suite Version >= 4.1.0 < 4.1.0sr04
DieboldnixdorfVynamic Security Suite Version >= 4.2.0 < 4.2.0sr04
DieboldnixdorfVynamic Security Suite Version >= 4.3.0 < 4.3.0sr03
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.456
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 4.6 0.9 3.6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-665 Improper Initialization

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.