CVE-2024-0674 MEDIUM

CVE-2024-0674: Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines

Vendor Lamassu
Product Bitcoin ATM Douro machines
Weakness CWE-269
Published January 30, 2024
Last update May 29, 2025

CVSS base score

6.3/10
Attack vector Physical
Attack complexity High
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissions by modifying the updatescript.js, inserting special code inside the script and creating the done.txt file. This would cause the watchdog process to run as root and execute the payload stored in the updatescript.js.

Key dates

02Disclosure timeline

January 30, 2024 CVE published
May 29, 2025 Record updated