TROYANOSYVIRUS
Volver a CVEs

CVE-2023-42134

MEDIUM
6.8

Descripcion

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subsequently local code execution via hidden command. The attacker must have physical USB access to the device in order to exploit this vulnerability.

Detalles CVE

Puntuacion CVSS v3.16.8
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataquePHYSICAL
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado1/15/2024
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0

Productos afectados

paxtechnology:a50paxtechnology:a920_propaxtechnology:paydroid

Debilidades (CWE)

CWE-912

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.