CVE Vulnerabilities

CVE-2023-33206

Improper Validation of Integrity Check Value

Published: Aug 08, 2024 | Modified: Aug 19, 2024
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails to validate symlinks during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the systems hard disk.

Weakness

The product does not validate or incorrectly validates the integrity check values or “checksums” of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Affected Software

NameVendorStart VersionEnd Version
Vynamic_security_suiteDieboldnixdorf*3.3.0sr16 (excluding)
Vynamic_security_suiteDieboldnixdorf4.0.0 (including)4.0.0sr06 (excluding)
Vynamic_security_suiteDieboldnixdorf4.1.0 (including)4.1.0sr04 (excluding)
Vynamic_security_suiteDieboldnixdorf4.2.0 (including)4.2.0sr03 (excluding)
Vynamic_security_suiteDieboldnixdorf4.3.0 (including)4.3.0sr01 (excluding)

Potential Mitigations

References