Dieboldnixdorf develops a focused portfolio of financial services and cash-management hardware and software, including ATM operating systems, security suites, and transaction-processing platforms that sit in critical banking infrastructure. Its vulnerability exposure clusters around data-integrity and access-control weaknesses—particularly missing or improper integrity checks, deserialization flaws, and privilege-management issues—that reflect the trust and validation demands of systems handling financial transactions and sensitive operational data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dieboldnixdorf over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-19559CRITICAL An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter. | Sep 11, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-70616HIGH A stack buffer overflow vulnerability exists in the Wincor Nixdorf wnBios64.sys kernel driver (version 1.2.0.0) in the IOCTL handler for code 0x80102058. The vulnerability is cause | Mar 5, 2026 | 7.8 | 26 | NO | NO |
CVE-2024-46916HIGH Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., l | Aug 29, 2025 | 8.1 | 26 | NO | NO |
CVE-2024-46917HIGH Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root during integrity validation. This allows code execution, recove | Aug 29, 2025 | 8.1 | 25 | NO | NO |
CVE-2023-33206MEDIUM Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails to validate symlinks during the Pre-Boot Authorization (PBA | Aug 8, 2024 | 6.8 | 21 | NO | NO |
CVE-2023-24063MEDIUM Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR10 fails to validate /etc/mtab during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical atta | Aug 8, 2024 | 6.8 | 21 | NO | NO |
CVE-2023-36344HIGH An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search path for required DLLs and not | Aug 8, 2023 | 7.8 | 21 | NO | NO |
CVE-2023-40261MEDIUM Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR02 fails to validate file attributes during the Pre-Boot Authorizati | Aug 8, 2024 | 6.8 | 20 | NO | NO |
CVE-2023-28865MEDIUM Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory contents of certain directories (e.g., ensuri | Aug 8, 2024 | 6.6 | 20 | NO | NO |
CVE-2023-24064MEDIUM Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical att | Aug 8, 2024 | 6.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dieboldnixdorf.
Media articles that mention a CVE ID that affects a product developed by Dieboldnixdorf — matched by CVE ID, not by vendor name.