CVE-2017-5634

The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended "Please select booking identification" UI step, and obtain administrative privileges and network access on the underlying Windows OS, by accessing a touch-screen print icon to manipulate the print dialog.
Configurations

Configuration 1 (hide)

cpe:2.3:a:norwegian-air:norwegian_air_kiosk:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:28

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/96230 - () http://www.securityfocus.com/bid/96230 -
References () https://bugemot.com/bug/190 - Third Party Advisory () https://bugemot.com/bug/190 - Third Party Advisory
References () https://www.youtube.com/watch?v=2j9gP5Qu2WA - Third Party Advisory () https://www.youtube.com/watch?v=2j9gP5Qu2WA - Third Party Advisory
References () https://www.youtube.com/watch?v=WSQW0ipnXQg - Third Party Advisory () https://www.youtube.com/watch?v=WSQW0ipnXQg - Third Party Advisory

Information

Published : 2017-02-09 16:59

Updated : 2024-11-21 03:28


NVD link : CVE-2017-5634

Mitre link : CVE-2017-5634

CVE.ORG link : CVE-2017-5634


JSON object : View

Products Affected

norwegian-air

  • norwegian_air_kiosk
CWE
CWE-668

Exposure of Resource to Wrong Sphere