PT-2025-35242 · Diebold Nixdorf +1 · Vynamic Security Suite +1

Published

2025-08-29

·

Updated

2025-08-29

·

CVE-2024-46916

CVSS v3.1
8.1
VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

Diebold Nixdorf Vynamic Security Suite versions through 4.3.0 SR06

Description:

The software contains functionality that allows the removal of critical system files before the filesystem is properly mounted, such as using a delete call in `/etc/rc.d/init.d/mountfs` to remove the `/etc/fstab` file. This can lead to code execution and, in some versions, enable recovery of TPM Disk Encryption keys and decryption of the Windows system partition.

Recommendations:

Update to a version later than 4.3.0 SR06.

Fix

Improper Access Control

Improper Privilege Management

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-46916

Affected Products

Vynamic Security Suite
Windows