← Back

CVE-2023-42137

nvd nist
Published: Jan 15, 2024Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have shell access to the device in order to exploit this vulnerability.

Affected (1)

1 product
Paydroid
Configuration A
1 platform
Running on/withPlatform Versions
Paxtechnology
A50
All versions
Configuration B
1 platform
Running on/withPlatform Versions
Paxtechnology
A6650
All versions
Configuration C
1 platform
Running on/withPlatform Versions
Paxtechnology
A800
All versions
Configuration D
1 platform
Running on/withPlatform Versions
Paxtechnology
A77
All versions
Configuration E
1 platform
Running on/withPlatform Versions
Paxtechnology
A920
All versions
Configuration F
1 platform
Running on/withPlatform Versions
Paxtechnology
A920 Pro
All versions
Configuration G
1 platform
Running on/withPlatform Versions
Paxtechnology
A920 Max
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 8.1.0_sagittarius_11.1.50_20230614
Running on/withPlatform Versions
Paxtechnology
D190
All versions

References (8)

Source: cvd@cert.pl
ExploitThird Party Advisory
Source: cvd@cert.pl
Third Party Advisory
Source: cvd@cert.pl
Third Party Advisory
Source: cvd@cert.pl
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.