CVE-2024-0674
Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.3EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
30 ene 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissions by modifying the updatescript.js, inserting special code inside the script and creating the done.txt file. This would cause the watchdog process to run as root and execute the payload stored in the updatescript.js.
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Lamassu · Bitcoin ATM Douro machines¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →