CVE-2024-0675
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/01/2024
Last modified:
08/02/2024
Description
Vulnerability of improper checking for unusual or exceptional conditions<br />
<br />
in Lamassu Bitcoin ATM Douro machines, in its 7.1 version,<br />
<br />
the exploitation of which could allow an attacker with physical access to the ATM to escape kiosk mode, access the underlying Xwindow interface and execute arbitrary commands as an unprivileged user.<br />
Impact
Base Score 3.x
6.80
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:lamassu:douro_firmware:7.1:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lamassu:douro:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lamassu:douro_ii_firmware:7.1:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lamassu:douro_ii:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



