« Volver al listado

CVE-2023-33206

Estado: AnalizadaMedia (6.8)—

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails to validate symlinks during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-33206",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-33206",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-09T16:21:37.460126Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:*:*:*:*:*:*:*:*"
          ],
          "vendor": "dieboldnixdorf",
          "product": "vynamic_security_suite",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.3.0 SR16",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.0.0 SR06",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.1.0 SR04",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.2.0 SR03",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.3.0 SR01",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-08-08T18:15:09.597",
  "references": [
    {
      "url": "https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Matt%20Burch%20-%20Where%E2%80%99s%20the%20Money%20-%20Defeating%20ATM%20Disk%20Encryption-white%20paper.pdf",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.dieboldnixdorf.com/en-us/banking/portfolio/software/security/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-354"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails to validate symlinks during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk."
    },
    {
      "lang": "es",
      "value": "Diebold Nixdorf Vynamic Security Suite (VSS) anterior a 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03 y 4.3.0 SR01 no puede validar los enlaces simbólicos durante el proceso Pre-Boot Authorization (PBA). Esto puede ser aprovechado por un atacante físico que pueda manipular el contenido del disco duro del sistema."
    }
  ],
  "lastModified": "2026-06-17T06:01:18.587",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "374241F8-B3F7-4B25-8C43-42FA7307BE69",
              "versionEndExcluding": "3.3.0sr16"
            },
            {
              "criteria": "cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B855A5E-4381-4313-A414-18085BAE4A90",
              "versionEndExcluding": "4.0.0sr06",
              "versionStartIncluding": "4.0.0"
            },
            {
              "criteria": "cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2F041A0-1166-4A02-BAD5-FF323E9A9C5B",
              "versionEndExcluding": "4.1.0sr04",
              "versionStartIncluding": "4.1.0"
            },
            {
              "criteria": "cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E631831-139E-445D-AA4B-6BA7D9980BC3",
              "versionEndExcluding": "4.2.0sr03",
              "versionStartIncluding": "4.2.0"
            },
            {
              "criteria": "cpe:2.3:a:dieboldnixdorf:vynamic_security_suite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62407A0F-9945-41F4-B5E6-7734E82D4003",
              "versionEndExcluding": "4.3.0sr01",
              "versionStartIncluding": "4.3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}