CVE-2017-5634
Summary
| CVE | CVE-2017-5634 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-02-09 16:59:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended "Please select booking identification" UI step, and obtain administrative privileges and network access on the underlying Windows OS, by accessing a touch-screen print icon to manipulate the print dialog. |
Risk And Classification
Problem Types: CWE-668
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Norwegian-air | Norwegian Air Kiosk | - | All | All | All |
| Application | Norwegian-air | Norwegian Air Kiosk | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Norwegian Air Shuttle Airline Kiosk CVE-2017-5634 Authentication Bypass Vulnerability | BID | www.securityfocus.com | |
| Norvegian - 02 - YouTube | MISC | www.youtube.com | Third Party Advisory |
| Norvegian - 01 - YouTube | MISC | www.youtube.com | Third Party Advisory |
| Airline kiosk - BUG-190 - BUGemot | MISC | bugemot.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.