Vulnerability Details CVE-2023-40261
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR02 fails to validate file attributes during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.3%
CVSS Severity
CVSS v3 Score 6.8
Products affected by CVE-2023-40261
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:-
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:3.3.0sr10
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:3.3.0sr12
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:3.3.0sr15
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:3.3.0sr16
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:3.3.0sr4
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:4.0.0
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:4.0.0sr04
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:4.0.0sr05
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:4.0.0sr06
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:4.1.0
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:4.1.0sr02
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:4.1.0sr03
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:4.2.0
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:4.2.0sr01
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:4.2.0sr02
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:4.2.0sr03
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:4.3.0
-
cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:4.3.0sr01