Weak password requirement vulnerability
in Lamassu Bitcoin ATM Douro machines, in its 7.1 version
, which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack.
in Lamassu Bitcoin ATM Douro machines, in its 7.1 version
, which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16467 | Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack. |
Fixes
Solution
The vulnerabilities have been resolved in version 8.1.5-1 and 8.1.6.
Workaround
No workaround given by the vendor.
References
History
Thu, 17 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-10-17T18:02:12.886Z
Reserved: 2024-01-18T11:38:17.175Z
Link: CVE-2024-0676
Updated: 2024-08-01T18:11:35.710Z
Status : Modified
Published: 2024-01-30T13:15:08.913
Modified: 2024-11-21T08:47:07.753
Link: CVE-2024-0676
No data.
OpenCVE Enrichment
No data.
EUVD