← Back

CVE-2023-42134

nvd nist
Published: Jan 15, 2024Modified: Nov 21, 2024

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD

Description

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subsequently local code execution via hidden command. The attacker must have physical USB access to the device in order to exploit this vulnerability.

Affected (1)

1 product
Paydroid
Configuration A
1 platform
Running on/withPlatform Versions
Paxtechnology
A920 Pro
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 8.1.0_sagittarius_v11.1.45_20230314
Running on/withPlatform Versions
Paxtechnology
A50
All versions

References (8)

Source: cvd@cert.pl
ExploitThird Party Advisory
Source: cvd@cert.pl
Third Party Advisory
Source: cvd@cert.pl
Third Party Advisory
Source: cvd@cert.pl
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.