Vulnerability Description
Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lamassu | Douro Firmware | 7.1 |
| Lamassu | Douro | - |
| Lamassu | Douro Ii Firmware | 7.1 |
| Lamassu | Douro Ii | - |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-lamaThird Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-lamaThird Party Advisory
FAQ
What is CVE-2024-0676?
CVE-2024-0676 is a vulnerability with a CVSS score of 5.6 (MEDIUM). Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a local user to interact with the machine where the application is installed, retrie...
How severe is CVE-2024-0676?
CVE-2024-0676 has been rated MEDIUM with a CVSS base score of 5.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-0676?
Check the references section above for vendor advisories and patch information. Affected products include: Lamassu Douro Firmware, Lamassu Douro, Lamassu Douro Ii Firmware, Lamassu Douro Ii.