CVE-2024-0676
30.01.2024, 13:15
Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack.Enginsight
Vendor | Product | Version |
---|---|---|
lamassu | douro_firmware | 7.1 |
lamassu | douro_ii_firmware | 7.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration