CVE-2024-0676
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/01/2024
Last modified:
08/02/2024
Description
Weak password requirement vulnerability <br />
<br />
in Lamassu Bitcoin ATM Douro machines, in its 7.1 version<br />
<br />
, which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:lamassu:douro_firmware:7.1:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lamassu:douro:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:lamassu:douro_ii_firmware:7.1:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lamassu:douro_ii:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



