ZeroHour

CVE-2017-5634

CVSS 3.0
6.6 medium
EPSS
<1%p36
Published
()
Modified
Description

The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended "Please select booking identification" UI step, and obtain administrative privileges and network access on the underlying Windows OS, by accessing a touch-screen print icon to manipulate the print dialog.

Vendors
norwegian-air
Products
norwegian air kiosk
Weakness
CWE-668
Vector
CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.