PT-2024-15740 · Lamassu · Lamassu Bitcoin Atm Douro
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Lamassu Bitcoin ATM Douro version 7.1
Description
The issue allows a local user to interact with the machine, retrieve stored hashes, and crack long 4-character passwords using a dictionary attack. This is due to a weak password requirement vulnerability in the affected version of the Lamassu Bitcoin ATM Douro machines.
Recommendations
For version 7.1, consider implementing stronger password requirements to prevent dictionary attacks, and restrict local user interaction with the machine to minimize the risk of exploitation. As a temporary workaround, consider disabling any features that allow the retrieval of stored hashes until a more secure solution is implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lamassu Bitcoin Atm Douro