Hotel check-in terminal bug spews out access codes for guest rooms
ID: ea063187-be33-551c-94e3-183a7a21874f
STIX ID: report--ea063187-be33-551c-94e3-183a7a21874f
Feed Name: The Register (Security)
Threat Score
A researcher discovered a flaw in an Ibis Budget self-service check-in terminal that returned booking details and room keycodes when a series of dashes was entered, exposing at least 87 bookings; Accor reproduced the issue and rolled out a software fix within a month. The vulnerability could enable physical theft or stalking, may affect other hotels using the same terminals across Europe, and there is no evidence it was exploited in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
