The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended "Please select booking identification" UI step, and obtain administrative privileges and network access on the underlying Windows OS, by accessing a touch-screen print icon to manipulate the print dialog.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/96230 | |
https://bugemot.com/bug/190 | Third Party Advisory |
https://www.youtube.com/watch?v=2j9gP5Qu2WA | Third Party Advisory |
https://www.youtube.com/watch?v=WSQW0ipnXQg | Third Party Advisory |
http://www.securityfocus.com/bid/96230 | |
https://bugemot.com/bug/190 | Third Party Advisory |
https://www.youtube.com/watch?v=2j9gP5Qu2WA | Third Party Advisory |
https://www.youtube.com/watch?v=WSQW0ipnXQg | Third Party Advisory |
Configurations
History
21 Nov 2024, 03:28
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/96230 - | |
References | () https://bugemot.com/bug/190 - Third Party Advisory | |
References | () https://www.youtube.com/watch?v=2j9gP5Qu2WA - Third Party Advisory | |
References | () https://www.youtube.com/watch?v=WSQW0ipnXQg - Third Party Advisory |
Information
Published : 2017-02-09 16:59
Updated : 2024-11-21 03:28
NVD link : CVE-2017-5634
Mitre link : CVE-2017-5634
CVE.ORG link : CVE-2017-5634
JSON object : View
Products Affected
norwegian-air
- norwegian_air_kiosk
CWE
CWE-668
Exposure of Resource to Wrong Sphere