Home

Description

EN DE

A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in the library wnport.sys of the component IOCTL Handler. Such manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 3.0.0.1 is able to mitigate this issue. Upgrading the affected component is recommended. The vendor was contacted beforehand and was able to provide a patch very early.

Es wurde eine Schwachstelle in Nixdorf Wincor PORT IO Driver up to 1.0.0.1 entdeckt. Betroffen hiervon ist die Funktion sub_11100 in der Bibliothek wnport.sys der Komponente IOCTL Handler. Die Bearbeitung verursacht stack-based buffer overflow. Der Angriff muss auf lokaler Ebene erfolgen. Der Exploit ist öffentlich verfügbar und könnte genutzt werden. Durch ein Upgrade auf Version 3.0.0.1 kann dieses Problem behoben werden. Ein Upgrade der betroffenen Komponente wird empfohlen.

PUBLISHED Reserved 2025-06-03 | Published 2025-10-18 | Updated 2025-10-18 | Assigner VulDB




HIGH: 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
HIGH: 7.8CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
6.8AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:OF/RC:C

Problem types

Stack-based Buffer Overflow

Memory Corruption

Product status

1.0.0.0
affected

1.0.0.1
affected

3.0.0.1
unaffected

Timeline

2025-10-18:Advisory disclosed
2025-10-18:VulDB entry created
2025-10-18:VulDB entry last update

Credits

rickqwq (VulDB User) reporter

References

vuldb.com/?id.329013 (VDB-329013 | Nixdorf Wincor PORT IO Driver IOCTL wnport.sys sub_11100 stack-based overflow) vdb-entry technical-description

vuldb.com/?ctiid.329013 (VDB-329013 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.604823 (Submit #604823 | Wincor Nixdorf Wincor Nixdorf PORT IO Driver <=1.0.0.1 Buffer Overflow) third-party-advisory

b.iakb.org/...Wincor-Nixdorf-PORT-IO-Driver-Buffer-Overflow/ broken-link exploit

download.dieboldnixdorf.com/ patch

cve.org (CVE-2025-5555)

nvd.nist.gov (CVE-2025-5555)

Download JSON