Weak password requirement vulnerability in Lamassu...
Moderate severity
Unreviewed
Published
Jan 30, 2024
to the GitHub Advisory Database
•
Updated Jan 30, 2024
Description
Published by the National Vulnerability Database
Jan 30, 2024
Published to the GitHub Advisory Database
Jan 30, 2024
Last updated
Jan 30, 2024
Weak password requirement vulnerability
in Lamassu Bitcoin ATM Douro machines, in its 7.1 version
, which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack.
References