Medium severity5.6NVD Advisory· Published Jan 30, 2024· Updated Jun 17, 2026
CVE-2024-0676
CVE-2024-0676
Description
Weak password requirement vulnerability
in Lamassu Bitcoin ATM Douro machines, in its 7.1 version
, which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:o:lamassu:douro_firmware:7.1:*:*:*:*:*:*:*
- cpe:2.3:o:lamassu:douro_ii_firmware:7.1:*:*:*:*:*:*:*
= 7.1+ 1 more
- (no CPE)range: = 7.1
- (no CPE)range: 7.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.