Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissions by modifying the updatescript.js, inserting special code inside the script and creating the done.txt file. This would cause the watchdog process to run as root and execute the payload stored in the updatescript.js.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16465 | Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissions by modifying the updatescript.js, inserting special code inside the script and creating the done.txt file. This would cause the watchdog process to run as root and execute the payload stored in the updatescript.js. |
Fixes
Solution
The vulnerabilities have been resolved in version 8.1.5-1 and 8.1.6.
Workaround
No workaround given by the vendor.
References
History
Thu, 29 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-05-29T15:05:33.779Z
Reserved: 2024-01-18T11:38:15.095Z
Link: CVE-2024-0674
Updated: 2024-08-01T18:11:35.674Z
Status : Modified
Published: 2024-01-30T13:15:08.330
Modified: 2024-11-21T08:47:07.360
Link: CVE-2024-0674
No data.
OpenCVE Enrichment
No data.
EUVD