CVE-2024-0676

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/01/2024
Last modified:
08/02/2024

Description

Weak password requirement vulnerability <br /> <br /> in Lamassu Bitcoin ATM Douro machines, in its 7.1 version<br /> <br /> , which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lamassu:douro_firmware:7.1:*:*:*:*:*:*:*
cpe:2.3:h:lamassu:douro:-:*:*:*:*:*:*:*
cpe:2.3:o:lamassu:douro_ii_firmware:7.1:*:*:*:*:*:*:*
cpe:2.3:h:lamassu:douro_ii:-:*:*:*:*:*:*:*