{"api_version":"1","generated_at":"2026-07-23T07:35:36+00:00","cve":"CVE-2017-5634","urls":{"html":"https://cve.report/CVE-2017-5634","api":"https://cve.report/api/cve/CVE-2017-5634.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-5634","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-5634"},"summary":{"title":"CVE-2017-5634","description":"The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended \"Please select booking identification\" UI step, and obtain administrative privileges and network access on the underlying Windows OS, by accessing a touch-screen print icon to manipulate the print dialog.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2017-02-09 16:59:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["CWE-668"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/96230","name":"96230","refsource":"BID","tags":[],"title":"Norwegian Air Shuttle Airline Kiosk CVE-2017-5634 Authentication Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.youtube.com/watch?v=WSQW0ipnXQg","name":"https://www.youtube.com/watch?v=WSQW0ipnXQg","refsource":"MISC","tags":["Third Party Advisory"],"title":"Norvegian - 02 - YouTube","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.youtube.com/watch?v=2j9gP5Qu2WA","name":"https://www.youtube.com/watch?v=2j9gP5Qu2WA","refsource":"MISC","tags":["Third Party Advisory"],"title":"Norvegian - 01 - YouTube","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugemot.com/bug/190","name":"https://bugemot.com/bug/190","refsource":"MISC","tags":["Third Party Advisory"],"title":"Airline kiosk - BUG-190 - BUGemot","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-5634","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-5634","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"5634","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"norwegian-air","cpe5":"norwegian_air_kiosk","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5634","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"norwegian-air","cpe5":"norwegian_air_kiosk","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-5634","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended \"Please select booking identification\" UI step, and obtain administrative privileges and network access on the underlying Windows OS, by accessing a touch-screen print icon to manipulate the print dialog."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://www.youtube.com/watch?v=2j9gP5Qu2WA","refsource":"MISC","url":"https://www.youtube.com/watch?v=2j9gP5Qu2WA"},{"name":"96230","refsource":"BID","url":"http://www.securityfocus.com/bid/96230"},{"name":"https://www.youtube.com/watch?v=WSQW0ipnXQg","refsource":"MISC","url":"https://www.youtube.com/watch?v=WSQW0ipnXQg"},{"name":"https://bugemot.com/bug/190","refsource":"MISC","url":"https://bugemot.com/bug/190"}]}},"nvd":{"publishedDate":"2017-02-09 16:59:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["CWE-668"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.6,"baseSeverity":"MEDIUM"},"exploitabilityScore":0.7,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:norwegian-air:norwegian_air_kiosk:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"5634","Ordinal":"102213","Title":"CVE-2017-5634","CVE":"CVE-2017-5634","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"5634","Ordinal":"1","NoteData":"The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended \"Please select booking identification\" UI step, and obtain administrative privileges and network access on the underlying Windows OS, by accessing a touch-screen print icon to manipulate the print dialog.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"5634","Ordinal":"2","NoteData":"2017-02-09","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"5634","Ordinal":"3","NoteData":"2017-02-28","Type":"Other","Title":"Modified"}]}}}