CVE-2025-5555 Details
Description
A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in the library wnport.sys of the component IOCTL Handler. Such manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 3.0.0.1 is able to mitigate this issue. Upgrading the affected component is recommended. The vendor was contacted beforehand and was able to provide a patch very early.
A stack-based buffer overflow vulnerability has been identified in the Wincor Nixdorf PORT IO Driver, specifically in versions through 1.0.0.1. The issue arises in the IOCTL Handler component, within the 'wnport.sys' library, particularly in the 'sub_11100' function. This vulnerability is caused by inadequate input validation, allowing local attackers to send oversized buffers that exceed the allocated stack space. Exploitation of this flaw can lead to memory corruption, system crashes, and potentially arbitrary code execution, especially since the driver's IOCTL functions can be accessed by low-privileged programs.
Users are advised to upgrade to version 3.0.0.1 of the PORT IO Driver, which addresses this vulnerability. The updated version is available for download from the Diebold Nixdorf Download Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 18, 2025CISA-ADP
Assessed Oct 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://b.iakb.org/2025/06/26/Wincor-Nixdorf-PORT-IO-Driver-Buffer-Overflow/ | [email protected] | Broken LinkExploit |
| https://download.dieboldnixdorf.com/ | [email protected] | Permission RequiredVendor |
| https://vuldb.com/?ctiid.329013 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.329013 | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/?submit.604823 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Nixdorf Wincorf PORT IO Driver | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Oct 18, 2025 | New CVE Received | [email protected] |
Volerion