Lamassu develops a focused line of Bitcoin automated teller machine (ATM) hardware and firmware products, primarily the Douro and Douro II systems, that connect to financial networks and manage cryptocurrency transactions. The observed vulnerabilities center on access-control and authentication weaknesses—including improper exception handling, permission preservation issues, improper privilege management, and weak password requirements—that reflect the security-critical nature of financial transaction hardware.
The number and severity of CVEs published that impact products developed by Lamassu over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0674HIGH Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissions by modifying the updatescri | Jan 30, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-0676HIGH Weak password requirement vulnerability
in Lamassu Bitcoin ATM Douro machines, in its 7.1 version
, which allows a local user to interact with the machine where the application | Jan 30, 2024 | 7.1 | 20 | NO | NO |
CVE-2024-0675MEDIUM Vulnerability of improper checking for unusual or exceptional conditions
in Lamassu Bitcoin ATM Douro machines, in its 7.1 version,
the exploitation of which could allow an atta | Jan 30, 2024 | 6.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lamassu.
Media articles that mention a CVE ID that affects a product developed by Lamassu — matched by CVE ID, not by vendor name.