7.1

CVE-2024-0676

Weak password requirement vulnerability 

in Lamassu Bitcoin ATM Douro machines, in its 7.1 version

, which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LamassuDouro Firmware Version7.1
   LamassuDouro Version-
LamassuDouro Ii Firmware Version7.1
   LamassuDouro Ii Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.112
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
cve-coordination@incibe.es 5.6 0.4 5.2
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-521 Weak Password Requirements

The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.