MEDIUM · 5.6

CVE-2024-0676

Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a local user to interact with the machine where the application is installed, retrie...

Vulnerability Description

Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack.

CVSS Score

5.6

MEDIUM

CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
LamassuDouro Firmware7.1
LamassuDouro-
LamassuDouro Ii Firmware7.1
LamassuDouro Ii-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-0676?

CVE-2024-0676 is a vulnerability with a CVSS score of 5.6 (MEDIUM). Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a local user to interact with the machine where the application is installed, retrie...

How severe is CVE-2024-0676?

CVE-2024-0676 has been rated MEDIUM with a CVSS base score of 5.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-0676?

Check the references section above for vendor advisories and patch information. Affected products include: Lamassu Douro Firmware, Lamassu Douro, Lamassu Douro Ii Firmware, Lamassu Douro Ii.