PT-2024-15740 · Lamassu · Lamassu Bitcoin Atm Douro

·

CVE-2024-0676

·

Published

2024-01-30

·

Updated

2024-02-21

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Lamassu Bitcoin ATM Douro version 7.1
Description The issue allows a local user to interact with the machine, retrieve stored hashes, and crack long 4-character passwords using a dictionary attack. This is due to a weak password requirement vulnerability in the affected version of the Lamassu Bitcoin ATM Douro machines.
Recommendations For version 7.1, consider implementing stronger password requirements to prevent dictionary attacks, and restrict local user interaction with the machine to minimize the risk of exploitation. As a temporary workaround, consider disabling any features that allow the retrieval of stored hashes until a more secure solution is implemented.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-0676

Affected Products

Lamassu Bitcoin Atm Douro