CVE-2024-0675

MEDIUM

Lamassu Bitcoin ATM Douro <7.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Vulnerability of improper checking for unusual or exceptional conditions in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, the exploitation of which could allow an attacker with physical access to the ATM to escape kiosk mode, access the underlying Xwindow interface and execute arbitrary commands as an unprivileged user.

Scores

CVSS v3 6.3
EPSS 0.0025
EPSS Percentile 15.7%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-754
Status published
Products (2)
lamassu/douro_firmware 7.1
lamassu/douro_ii_firmware 7.1
Published Jan 30, 2024
Tracked Since Feb 18, 2026