CVE-2024-0676: Lamassu Douro Firmware

High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.

Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack.

Affected products

  • Lamassu Douro Firmware: version 7.1 only
  • Lamassu Douro Ii Firmware: version 7.1 only

Published 2024-01-30. Last modified 2026-06-17.