Hotel Check-in Kiosks Expose Guest Data, Room Keys
ID: 13e94691-416d-598c-b9bd-06759e619e8a
STIX ID: report--13e94691-416d-598c-b9bd-06759e619e8a
Feed Name: Dark Reading
A kiosk-mode bypass vulnerability (CVE-2024-37364, CVSS 6.8) in Ariane Allegro hotel self-check-in terminals can be triggered by simple input, causing the application to hang and allowing an attacker with physical access to reach the Windows desktop, execute code, access guest reservations/PII, and potentially create RFID room keys; the vendor released a fix for affected systems and operators are advised to update terminals, isolate them on separate network segments, and restrict physical access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
