← Back

CVE-2023-4818

nvd nist
Published: Jan 15, 2024Modified: Jun 17, 2025

JSON object

Loading...
7.6
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 6.0
Source: NVD

Description

PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by PAX can be used.  The attacker must have physical USB access to the device in order to exploit this vulnerability.

Affected (1)

1 product
Paydroid
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 7.1.2_aquarius_11.1.50_20230614
Running on/withPlatform Versions
Paxtechnology
A920
All versions

References (8)

Source: cvd@cert.pl
ExploitThird Party Advisory
Source: cvd@cert.pl
Third Party Advisory
Source: cvd@cert.pl
Third Party Advisory
Source: cvd@cert.pl
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.