NA

CVE-2024-0676

Published: 30/01/2024 Updated: 08/02/2024
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8

Vulnerability Summary

Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack.

Vulnerable Product Search on Vulmon Subscribe to Product

lamassu douro_firmware 7.1

lamassu douro_ii_firmware 7.1