Dieboldnixdorf

    Dashboard / Vendors

    Products: 7
    Vulnerabilities: 15
    Known Exploited: 0
    1
    Critical Level Threats
    8
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-70616

    A stack buffer overflow vulnerability exists in the Wincor Nixdorf wnBios64.sys kernel driver (version 1.2.0.0) in the IOCTL handler for code 0x80102058. The vulnerability is caused by missing bounds checking on the user-controlled Options parameter before copying data into a 40-byte stack buffer (Src[40]) using memmove. An attacker with local access can exploit this vulnerability by sending a crafted IOCTL request with Options > 40, causing a stack buffer overflow that may lead to kernel code execution, local privilege escalation, or denial of service (system crash). Additionally, the same IOCTL handler can leak kernel addresses and other sensitive stack data when reading beyond the buffer boundaries.

    Last Modified: Mar 10, 2026
    Published: Mar 05, 2026

    CVE-2025-5555

    Nixdorf Wincor PORT IO Driver IOCTL wnport.sys sub_11100 stack-based overflow

    Last Modified: Apr 15, 2026
    Published: Oct 18, 2025

    CVE-2024-46916

    Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., leveraging a delete call in /etc/rc.d/init.d/mountfs to remove the /etc/fstab file). This can allow code execution and, in some versions, enable recovery of TPM Disk Encryption keys and decryption of the Windows system partition.

    Last Modified: Sep 09, 2025
    Published: Aug 29, 2025

    CVE-2024-46917

    Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root during integrity validation. This allows code execution, recovery of TPM Disk Encryption keys, decryption of the Windows system partition, and full control of the Windows OS, e.g., through ~/.profile changes.

    Last Modified: Sep 09, 2025
    Published: Aug 29, 2025

    CVE-2024-45246

    Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element

    Last Modified: Apr 15, 2026
    Published: Oct 06, 2024
    Items Per Page