Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lamassu

First CVE: Jan 30, 2024Active for: 2 yearsTotal CVEs: 3

Lamassu develops a focused line of Bitcoin automated teller machine (ATM) hardware and firmware products, primarily the Douro and Douro II systems, that connect to financial networks and manage cryptocurrency transactions. The observed vulnerabilities center on access-control and authentication weaknesses—including improper exception handling, permission preservation issues, improper privilege management, and weak password requirements—that reflect the security-critical nature of financial transaction hardware.

FAUCET AI Generated
3
Total CVEs
More Total CVEs than 72% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lamassu over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2024
2 years ago
Most Recent CVE
Jan 30, 2024
906 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-0674HIGH
Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissions by modifying the updatescri
Jan 30, 20247.822NONO
CVE-2024-0676HIGH
Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a local user to interact with the machine where the application
Jan 30, 20247.120NONO
CVE-2024-0675MEDIUM
Vulnerability of improper checking for unusual or exceptional conditions in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, the exploitation of which could allow an atta
Jan 30, 20246.820NONO
View all 3 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products3 CVEs
33%
67%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (66.7%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical1 (33.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (66.7%)
High0 (0.0%)
None1 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lamassu.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lamassu — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lamassu's Products

View all 1 CNAs →

Top CWEs