PT-2025-35242 · Diebold Nixdorf +1 · Vynamic Security Suite +1
Published
2025-08-29
·
Updated
2025-08-29
·
CVE-2024-46916
Published
2025-08-29
·
Updated
2025-08-29
·
CVE-2024-46916
8.1
High
Base vector | Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Diebold Nixdorf Vynamic Security Suite versions through 4.3.0 SR06
Description:
The software contains functionality that allows the removal of critical system files before the filesystem is properly mounted, such as using a delete call in `/etc/rc.d/init.d/mountfs` to remove the `/etc/fstab` file. This can lead to code execution and, in some versions, enable recovery of TPM Disk Encryption keys and decryption of the Windows system partition.
Recommendations:
Update to a version later than 4.3.0 SR06.
Fix
Improper Access Control
Improper Privilege Management
Incorrect Default Permissions